SOC 2 Certification: How to Get One (Step-by-Step Guide)

11 min read
SOC 2 Certification: How to Get One (Step-by-Step Guide)

To get SOC 2 certification, you hire a licensed CPA firm to audit your security controls against the AICPA’s Trust Services Criteria. Before the audit, you define your scope, choose a Type I or Type II report, write policies, implement controls like access reviews, change management, vulnerability scanning, logging, and incident response, and collect evidence that those controls work. Most companies get a Type I report in 2 to 4 months and a Type II report in 6 to 12 months.

TL;DR: The audit itself is the easy part. The hard part is building and running the controls the auditor tests. This guide walks through every step, and shows how Espresso Labs automates the work so lean teams can get SOC 2 without hiring a compliance department.


Is It SOC 2 “Certification” or “Attestation”?

Technically, nobody gets “certified” in SOC 2. A CPA firm issues an attestation report: a formal opinion on whether your controls are designed (and, for Type II, operating) effectively. There’s no certificate and no central registry.

In practice, buyers, sales teams, and search engines all say “SOC 2 certification,” and they mean the same thing: a clean SOC 2 report you can hand to customers during security review. This guide uses both terms.

If you’re new to the framework, start with What Is SOC 2.


SOC 1 vs. SOC 2 vs. SOC 3

SOC stands for System and Organization Controls (originally Service Organization Controls). The AICPA defines three report types:

ReportWhat It CoversWho Reads It
SOC 1Controls that affect your customers’ financial reportingCustomers’ auditors and finance teams
SOC 2Security, availability, processing integrity, confidentiality, and privacy controlsCustomers’ security, IT, and procurement teams (under NDA)
SOC 3A short, public summary of a SOC 2Anyone, often posted on a website

If a customer asked for your “SOC report” during a security questionnaire, they almost certainly mean SOC 2.


SOC 2 Type I vs. Type II: Which One Do You Need?

Type I evaluates whether your controls are properly designed at a single point in time. It’s faster and cheaper, and it’s a common first step when a deal is waiting on a report.

Type II evaluates whether your controls actually operated effectively over an observation period, usually 3 to 12 months. The auditor samples evidence across that window, and any lapses are written into the report as exceptions. Type II is what most enterprise buyers ultimately require.

Type IType II
What’s testedControl designControl design and operating effectiveness
Time periodA single date3 to 12 month observation window
Typical timeline2 to 4 months6 to 12 months
Best forUnblocking a near-term dealLong-term enterprise sales

A practical approach: get a Type I to satisfy immediate requests, and start your Type II observation window the same day. Whoever keeps your controls running during that window determines whether you pass.


The Five Trust Services Criteria

Every SOC 2 audit is built on the AICPA’s Trust Services Criteria. Only Security is mandatory. You choose the others based on what you promise customers.

  1. Security (required): Protecting systems against unauthorized access, including firewalls, access control, breach response, and monitoring.
  2. Availability: Keeping systems up and accessible to authorized users as committed in your SLAs.
  3. Processing Integrity: Ensuring data is processed completely, accurately, on time, and only when authorized.
  4. Confidentiality: Protecting information designated as confidential from unauthorized disclosure.
  5. Privacy: Governing how personal information is collected, used, retained, disclosed, and disposed of.

Most B2B companies scope Security, often with Availability and Confidentiality. Privacy usually applies to companies handling consumer data directly. Every criterion you add increases audit cost and preparation work, so only include what your customers actually need.


How to Get SOC 2 Certified in 8 Steps

Step 1: Define Your Scope

Decide which products, services, systems, people, and data are in the audit. For B2B companies, the rule of thumb is to include the services customers actually rely on and ask about in security reviews. A scope that’s too narrow produces a report buyers won’t accept. A scope that’s too broad adds cost and risk for no benefit.

Step 2: Choose Your Report Type and Criteria

Pick Type I or Type II, and select which Trust Services Criteria apply. Ask your biggest prospects what they need before deciding. Many will tell you exactly.

Step 3: Run a Readiness Assessment (Gap Analysis)

Compare your current controls against SOC 2 requirements and list every gap. Many auditors offer readiness assessments. Choose one that folds that work into the formal audit rather than charging you twice for the same discovery.

Step 4: Write and Update Policies

SOC 2 expects documented policies covering information security, access control, change management, risk assessment, vendor management, incident response, business continuity, acceptable use, and more. Policies must reflect what you actually do, because the auditor will check.

Step 5: Implement the Controls

This is where most of the effort goes, and where most companies stall. The controls auditors focus on most are covered in detail below: access control, change control, risk and vendor management, internal audit, and technical security controls.

Step 6: Collect Evidence

Auditors don’t take your word for it. They need screenshots, logs, tickets, access review records, training completions, and configuration exports showing each control is in place. For Type II, that evidence has to cover the entire observation window, not just the week before the audit.

Step 7: Choose a CPA Auditor and Complete the Audit

Only a licensed CPA firm can issue a SOC 2 report. When comparing auditors, weigh:

  • Cost: Annual audit fees, and what’s included. See How Much Does SOC 2 Compliance Cost?
  • SOC 2 experience: Firms that specialize in SOC 2 and know your industry run smoother audits.
  • Committed timeline: Get milestones in writing, including when you’ll receive the final report.
  • Readiness integration: Prefer auditors whose readiness work carries into the audit instead of duplicating it.

Step 8: Maintain Compliance and Renew Annually

A SOC 2 report is generally considered current for 12 months. Customers will ask for a fresh one every year, which means your controls need to keep running, and producing evidence, continuously.


What Auditors Look at Most Closely

Access Control

Who has access to what, and at what level? Auditors want to see regular access reviews across every key system: identity providers, cloud platforms, networking equipment, servers, VPNs, and SaaS applications. They’ll check that departing employees are deprovisioned promptly and that privileged access is limited. Running your own access review before the audit almost always turns up stale accounts and over-permissioned users. Better you find them than the auditor.

Change Control

Every change to software, infrastructure, configuration, or networking should be requested, approved, tested, and documented the same way every time. A ticketing system is the most reliable way to create that consistent trail.

Risk Management and Vendor Management

You need a formal, repeatable risk assessment process where management decides whether to avoid, mitigate, transfer, or accept each risk. Vendor oversight should be tiered by importance: the cloud provider that processes customer data needs far more scrutiny than your office supply vendor.

Internal Audit

Someone needs to independently check that your SOC 2 program is working. Independence matters: people shouldn’t audit systems they built or maintain. Smaller companies often use a cross-department reviewer or an outside party to fill this role.


The Technical Security Controls You’ll Need

File Integrity Monitoring

Regularly check critical system files for unauthorized or malicious changes. It’s one of the most frequently overlooked controls. Some existing tools can cover it, but many companies need to add software.

Vulnerability Management

Continuously scan laptops, servers, network devices, applications, and cloud resources for vulnerabilities, and remediate what you find on a defined timeline. Auditors look for both the scanning and proof of the fixes.

Incident Response

Maintain a documented incident response plan covering preparation, detection and analysis, containment, eradication and recovery, and post-incident review. Test it regularly with tabletop exercises, and identify outside technical and legal resources ahead of time.

Logging and Monitoring

Log key security events across your infrastructure and applications, and actively monitor those logs for anomalies. Collecting logs nobody reviews won’t satisfy an auditor.

Endpoint and Identity Security

Expect to show encrypted devices, endpoint protection, MFA everywhere it’s supported, and security awareness training for all employees.


Why Getting SOC 2 Is So Hard for Lean Teams

None of the steps above is conceptually difficult. The problem is volume and consistency. A Type II audit asks you to prove that dozens of controls operated correctly every day for months. For a company without a dedicated IT, security, or compliance team, that typically means:

  • Engineers pulled off product work to take screenshots and chase evidence
  • A GRC platform that flags gaps but leaves your team to fix them
  • Consultants who deliver a gap report and leave before the controls are built
  • A scramble before every audit, and a real risk of exceptions in the report

This is why many companies searching for how to get SOC 2 end up comparing SOC 2 consultants and SOC 2 compliance software, and finding that neither fully solves the problem.


How Espresso Labs Automates SOC 2

Espresso Labs takes a different approach. Instead of telling you what’s missing, we act as your virtual IT, cybersecurity, and compliance team and do the work. Here’s how that maps to each step above:

SOC 2 StepDoing It YourselfWith Espresso Labs
Scoping and readinessHire a consultant or learn the frameworkWe scope your environment and identify gaps with you
PoliciesWrite and maintain dozens of documentsPolicies provided and mapped to automated playbooks that enforce them
Access controlManual quarterly reviews across every systemAutomated access reviews and deprovisioning
Vulnerability managementBuy a scanner, triage findings, chase fixesContinuous scanning with remediation handled for you
Logging and monitoringStand up a SIEM and staff it24/7 monitoring and threat response included
Endpoint securityDeploy and manage EDR, encryption, and MDMDevices secured and managed for you
Evidence collectionScreenshots and spreadsheets before every auditAudit-ready evidence collected automatically, every day
AuditFind and vet a CPA firm on your ownIntroduction to an independent CPA audit partner
Annual renewalRepeat the scrambleControls keep running, so the next audit is routine

The result: audit prep becomes a byproduct of daily operations instead of a sprint. When the auditor asks for evidence from month four of your observation window, it’s already there.

Because the same platform covers CMMC, HIPAA, ISO 27001, and other frameworks, adding a second framework later doesn’t mean starting over.

Learn more about SOC 2 for startups, see our Compliance as a Service, or check out our SOC 2 offer to get compliant in weeks.


Key Takeaways

  • SOC 2 “certification” is an attestation report issued by a licensed CPA firm against the AICPA Trust Services Criteria.
  • Security is the only required criterion. Add Availability, Confidentiality, Processing Integrity, or Privacy only if customers need them.
  • Type I proves control design at a point in time. Type II proves controls operated over 3 to 12 months, and it’s what most enterprise buyers want.
  • The eight steps: scope, choose report type, assess gaps, write policies, implement controls, collect evidence, complete the audit, and maintain compliance.
  • Auditors focus on access control, change control, risk and vendor management, internal audit, vulnerability management, incident response, and logging.
  • Automation shortens the path. A managed service that implements controls and collects evidence continuously removes most of the manual work.

Sources and further reading

How to Get SOC 2: FAQs

Ready to Get Started?

Espresso Labs implements and operates your SOC 2 controls, collects audit evidence automatically, and connects you with an independent CPA auditor, so you get your report without hiring a compliance team.

Get SOC 2 with Espresso Labs