SOC 2 Certification: How to Get One (Step-by-Step Guide)
To get SOC 2 certification, you hire a licensed CPA firm to audit your security controls against the AICPA’s Trust Services Criteria. Before the audit, you define your scope, choose a Type I or Type II report, write policies, implement controls like access reviews, change management, vulnerability scanning, logging, and incident response, and collect evidence that those controls work. Most companies get a Type I report in 2 to 4 months and a Type II report in 6 to 12 months.
TL;DR: The audit itself is the easy part. The hard part is building and running the controls the auditor tests. This guide walks through every step, and shows how Espresso Labs automates the work so lean teams can get SOC 2 without hiring a compliance department.
Is It SOC 2 “Certification” or “Attestation”?
Technically, nobody gets “certified” in SOC 2. A CPA firm issues an attestation report: a formal opinion on whether your controls are designed (and, for Type II, operating) effectively. There’s no certificate and no central registry.
In practice, buyers, sales teams, and search engines all say “SOC 2 certification,” and they mean the same thing: a clean SOC 2 report you can hand to customers during security review. This guide uses both terms.
If you’re new to the framework, start with What Is SOC 2.
SOC 1 vs. SOC 2 vs. SOC 3
SOC stands for System and Organization Controls (originally Service Organization Controls). The AICPA defines three report types:
| Report | What It Covers | Who Reads It |
|---|---|---|
| SOC 1 | Controls that affect your customers’ financial reporting | Customers’ auditors and finance teams |
| SOC 2 | Security, availability, processing integrity, confidentiality, and privacy controls | Customers’ security, IT, and procurement teams (under NDA) |
| SOC 3 | A short, public summary of a SOC 2 | Anyone, often posted on a website |
If a customer asked for your “SOC report” during a security questionnaire, they almost certainly mean SOC 2.
SOC 2 Type I vs. Type II: Which One Do You Need?
Type I evaluates whether your controls are properly designed at a single point in time. It’s faster and cheaper, and it’s a common first step when a deal is waiting on a report.
Type II evaluates whether your controls actually operated effectively over an observation period, usually 3 to 12 months. The auditor samples evidence across that window, and any lapses are written into the report as exceptions. Type II is what most enterprise buyers ultimately require.
| Type I | Type II | |
|---|---|---|
| What’s tested | Control design | Control design and operating effectiveness |
| Time period | A single date | 3 to 12 month observation window |
| Typical timeline | 2 to 4 months | 6 to 12 months |
| Best for | Unblocking a near-term deal | Long-term enterprise sales |
A practical approach: get a Type I to satisfy immediate requests, and start your Type II observation window the same day. Whoever keeps your controls running during that window determines whether you pass.
The Five Trust Services Criteria
Every SOC 2 audit is built on the AICPA’s Trust Services Criteria. Only Security is mandatory. You choose the others based on what you promise customers.
- Security (required): Protecting systems against unauthorized access, including firewalls, access control, breach response, and monitoring.
- Availability: Keeping systems up and accessible to authorized users as committed in your SLAs.
- Processing Integrity: Ensuring data is processed completely, accurately, on time, and only when authorized.
- Confidentiality: Protecting information designated as confidential from unauthorized disclosure.
- Privacy: Governing how personal information is collected, used, retained, disclosed, and disposed of.
Most B2B companies scope Security, often with Availability and Confidentiality. Privacy usually applies to companies handling consumer data directly. Every criterion you add increases audit cost and preparation work, so only include what your customers actually need.
How to Get SOC 2 Certified in 8 Steps
Step 1: Define Your Scope
Decide which products, services, systems, people, and data are in the audit. For B2B companies, the rule of thumb is to include the services customers actually rely on and ask about in security reviews. A scope that’s too narrow produces a report buyers won’t accept. A scope that’s too broad adds cost and risk for no benefit.
Step 2: Choose Your Report Type and Criteria
Pick Type I or Type II, and select which Trust Services Criteria apply. Ask your biggest prospects what they need before deciding. Many will tell you exactly.
Step 3: Run a Readiness Assessment (Gap Analysis)
Compare your current controls against SOC 2 requirements and list every gap. Many auditors offer readiness assessments. Choose one that folds that work into the formal audit rather than charging you twice for the same discovery.
Step 4: Write and Update Policies
SOC 2 expects documented policies covering information security, access control, change management, risk assessment, vendor management, incident response, business continuity, acceptable use, and more. Policies must reflect what you actually do, because the auditor will check.
Step 5: Implement the Controls
This is where most of the effort goes, and where most companies stall. The controls auditors focus on most are covered in detail below: access control, change control, risk and vendor management, internal audit, and technical security controls.
Step 6: Collect Evidence
Auditors don’t take your word for it. They need screenshots, logs, tickets, access review records, training completions, and configuration exports showing each control is in place. For Type II, that evidence has to cover the entire observation window, not just the week before the audit.
Step 7: Choose a CPA Auditor and Complete the Audit
Only a licensed CPA firm can issue a SOC 2 report. When comparing auditors, weigh:
- Cost: Annual audit fees, and what’s included. See How Much Does SOC 2 Compliance Cost?
- SOC 2 experience: Firms that specialize in SOC 2 and know your industry run smoother audits.
- Committed timeline: Get milestones in writing, including when you’ll receive the final report.
- Readiness integration: Prefer auditors whose readiness work carries into the audit instead of duplicating it.
Step 8: Maintain Compliance and Renew Annually
A SOC 2 report is generally considered current for 12 months. Customers will ask for a fresh one every year, which means your controls need to keep running, and producing evidence, continuously.
What Auditors Look at Most Closely
Access Control
Who has access to what, and at what level? Auditors want to see regular access reviews across every key system: identity providers, cloud platforms, networking equipment, servers, VPNs, and SaaS applications. They’ll check that departing employees are deprovisioned promptly and that privileged access is limited. Running your own access review before the audit almost always turns up stale accounts and over-permissioned users. Better you find them than the auditor.
Change Control
Every change to software, infrastructure, configuration, or networking should be requested, approved, tested, and documented the same way every time. A ticketing system is the most reliable way to create that consistent trail.
Risk Management and Vendor Management
You need a formal, repeatable risk assessment process where management decides whether to avoid, mitigate, transfer, or accept each risk. Vendor oversight should be tiered by importance: the cloud provider that processes customer data needs far more scrutiny than your office supply vendor.
Internal Audit
Someone needs to independently check that your SOC 2 program is working. Independence matters: people shouldn’t audit systems they built or maintain. Smaller companies often use a cross-department reviewer or an outside party to fill this role.
The Technical Security Controls You’ll Need
File Integrity Monitoring
Regularly check critical system files for unauthorized or malicious changes. It’s one of the most frequently overlooked controls. Some existing tools can cover it, but many companies need to add software.
Vulnerability Management
Continuously scan laptops, servers, network devices, applications, and cloud resources for vulnerabilities, and remediate what you find on a defined timeline. Auditors look for both the scanning and proof of the fixes.
Incident Response
Maintain a documented incident response plan covering preparation, detection and analysis, containment, eradication and recovery, and post-incident review. Test it regularly with tabletop exercises, and identify outside technical and legal resources ahead of time.
Logging and Monitoring
Log key security events across your infrastructure and applications, and actively monitor those logs for anomalies. Collecting logs nobody reviews won’t satisfy an auditor.
Endpoint and Identity Security
Expect to show encrypted devices, endpoint protection, MFA everywhere it’s supported, and security awareness training for all employees.
Why Getting SOC 2 Is So Hard for Lean Teams
None of the steps above is conceptually difficult. The problem is volume and consistency. A Type II audit asks you to prove that dozens of controls operated correctly every day for months. For a company without a dedicated IT, security, or compliance team, that typically means:
- Engineers pulled off product work to take screenshots and chase evidence
- A GRC platform that flags gaps but leaves your team to fix them
- Consultants who deliver a gap report and leave before the controls are built
- A scramble before every audit, and a real risk of exceptions in the report
This is why many companies searching for how to get SOC 2 end up comparing SOC 2 consultants and SOC 2 compliance software, and finding that neither fully solves the problem.
How Espresso Labs Automates SOC 2
Espresso Labs takes a different approach. Instead of telling you what’s missing, we act as your virtual IT, cybersecurity, and compliance team and do the work. Here’s how that maps to each step above:
| SOC 2 Step | Doing It Yourself | With Espresso Labs |
|---|---|---|
| Scoping and readiness | Hire a consultant or learn the framework | We scope your environment and identify gaps with you |
| Policies | Write and maintain dozens of documents | Policies provided and mapped to automated playbooks that enforce them |
| Access control | Manual quarterly reviews across every system | Automated access reviews and deprovisioning |
| Vulnerability management | Buy a scanner, triage findings, chase fixes | Continuous scanning with remediation handled for you |
| Logging and monitoring | Stand up a SIEM and staff it | 24/7 monitoring and threat response included |
| Endpoint security | Deploy and manage EDR, encryption, and MDM | Devices secured and managed for you |
| Evidence collection | Screenshots and spreadsheets before every audit | Audit-ready evidence collected automatically, every day |
| Audit | Find and vet a CPA firm on your own | Introduction to an independent CPA audit partner |
| Annual renewal | Repeat the scramble | Controls keep running, so the next audit is routine |
The result: audit prep becomes a byproduct of daily operations instead of a sprint. When the auditor asks for evidence from month four of your observation window, it’s already there.
Because the same platform covers CMMC, HIPAA, ISO 27001, and other frameworks, adding a second framework later doesn’t mean starting over.
Learn more about SOC 2 for startups, see our Compliance as a Service, or check out our SOC 2 offer to get compliant in weeks.
Key Takeaways
- SOC 2 “certification” is an attestation report issued by a licensed CPA firm against the AICPA Trust Services Criteria.
- Security is the only required criterion. Add Availability, Confidentiality, Processing Integrity, or Privacy only if customers need them.
- Type I proves control design at a point in time. Type II proves controls operated over 3 to 12 months, and it’s what most enterprise buyers want.
- The eight steps: scope, choose report type, assess gaps, write policies, implement controls, collect evidence, complete the audit, and maintain compliance.
- Auditors focus on access control, change control, risk and vendor management, internal audit, vulnerability management, incident response, and logging.
- Automation shortens the path. A managed service that implements controls and collects evidence continuously removes most of the manual work.
Sources and further reading