What Is SOC 2
SOC 2 (System and Organization Controls 2) is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates how a service organization manages customer data. It has become the default trust signal that SaaS companies, cloud providers, and technology vendors use to prove to customers, investors, and partners that they take data security seriously.
The Short Answer
SOC 2 is not a certification and there is no governing body that “passes” or “fails” you. It’s an attestation: an independent CPA firm audits your organization’s controls against the AICPA’s Trust Services Criteria and issues a report describing what it found. Customers, especially enterprise buyers, increasingly require a current SOC 2 report before they’ll sign a contract or complete a security review.
Unlike CMMC, which is a DoD-mandated certification enforced through contract clauses, SOC 2 is market-driven. Nothing in federal law requires it, but for any company selling software or hosted services to other businesses, the absence of a SOC 2 report is often a deal-breaker in procurement.
Why SOC 2 Exists
As companies moved critical data and infrastructure to third-party vendors, customers needed a standardized way to evaluate a vendor’s security posture without conducting their own audit of every supplier. The AICPA created the SOC framework to fill that gap: SOC 1 covers controls relevant to a customer’s financial reporting, while SOC 2 covers controls relevant to security, availability, and data handling, which is what most technology buyers actually care about.
The Five Trust Services Criteria
Every SOC 2 audit is scoped against some combination of five Trust Services Criteria (TSC):
- Security (the “Common Criteria”): Required for every SOC 2 report. Covers protection against unauthorized access, including access controls, network security, and change management.
- Availability: Whether systems are available for operation and use as committed or agreed, covering uptime, monitoring, and disaster recovery.
- Processing Integrity: Whether system processing is complete, valid, accurate, timely, and authorized.
- Confidentiality: Whether information designated as confidential is protected as committed or agreed.
- Privacy: How personal information is collected, used, retained, disclosed, and disposed of.
Security is mandatory for every SOC 2 report. Most companies add Availability and Confidentiality; Processing Integrity and Privacy are typically scoped in only when directly relevant to the service being audited.
SOC 2 Type I vs. Type II
- Type I evaluates whether your controls are suitably designed as of a specific point in time. It answers: “Do you have the right controls in place today?”
- Type II evaluates whether those controls operated effectively over an observation period, typically 3–12 months. It answers: “Did those controls actually work, consistently, over time?”
Type II is the report most enterprise customers expect, since it demonstrates sustained operation rather than a one-time snapshot. Many companies start with a Type I report to establish a baseline, then move to a Type II report on their next audit cycle.
Who Needs SOC 2
SOC 2 is most commonly required for:
- SaaS and cloud software companies storing or processing customer data
- Managed service providers and IT vendors with access to customer systems
- Data processing and analytics companies
- Any vendor selling into enterprise customers whose procurement or security teams require it as a condition of doing business
How the Audit Process Works
- Scoping: Determine which Trust Services Criteria and systems are in scope for the audit
- Readiness assessment: Identify gaps between current controls and SOC 2 requirements before the formal audit
- Remediation: Close identified gaps, implement missing controls, and build supporting documentation
- Observation period (Type II only): Controls operate and generate evidence over the audit window
- Audit fieldwork: An independent CPA firm licensed to perform SOC 2 audits examines evidence, interviews staff, and tests controls
- Report issuance: The CPA firm issues the SOC 2 report, which you can share directly with customers under NDA
How Espresso Labs Helps
Espresso Labs implements and continuously operates the technical controls SOC 2 auditors look for, including access management, encryption, logging, vulnerability management, and incident response, while maintaining the evidence trail auditors need. For a realistic breakdown of what a SOC 2 audit costs by company size and report type, see how much SOC 2 compliance costs.