SOC 2 readiness, in plain English.
What it is, whether you need it, and what it actually takes to get ready.
What SOC 2 is
SOC 2 (System and Organization Controls 2) is a report from an independent CPA firm on how well a company's controls protect customer data. It is built on the AICPA's Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is part of every SOC 2 report; the other four are added based on what your customers need.
There are two types. A Type I report looks at whether your controls are designed properly at a single point in time. A Type II report looks at whether they actually worked over a period of time, commonly several months to a year, and it is usually the one larger buyers prefer.
Do you actually need one?
SOC 2 is not a law, and nobody is required to have it. It becomes a requirement when a customer, partner, or contract asks for it, which is common for software and service companies that handle other businesses' data.
Before you spend months on it, find out exactly what the customer needs. Sometimes a strong set of security policies and a well-answered questionnaire is enough, at least for now. If several customers are asking, that is usually the signal that it is time.
What readiness involves
- Scoping which systems and Trust Services Criteria are in play
- A gap assessment against those criteria, so you know what is missing before an auditor does
- Closing the gaps: access controls, change management, logging and monitoring, vendor management, incident response, and employee onboarding and offboarding
- Writing the policies and procedures an auditor expects to see, in language your team can actually follow
- Setting up how you will collect and keep evidence that controls are working
- A readiness check, then a handoff to your chosen audit firm
How long it takes
It varies a lot with company size and where you are starting from, so we will not quote a one-size-fits-all number. Plan for months, not weeks, and keep in mind that a Type II report also needs an observation period before the audit can conclude.
What we do, and what we do not
What we do
We prepare you: gap assessment, remediation guidance, policies, and evidence organization, so your audit goes smoothly.
What we do not do
We do not issue the report. Only an independent, licensed CPA firm can do that, and no one can honestly promise a clean opinion in advance. Our job is to make sure you walk in prepared.
Related guides
SOC 2 questions, answered.
How much does SOC 2 cost?
There are two separate costs: the readiness work, and the audit fee from your CPA firm. Both depend on your scope and starting point. We scope and quote our work before we begin, and your auditor quotes the audit separately.
Should we start with Type I or Type II?
It depends on what your customer is asking for, so ask them first. Some companies start with a Type I report to unblock a deal and move to Type II later; others go straight to Type II.
Do we need a compliance automation platform for SOC 2?
SOC 2 itself does not require one. These platforms can make evidence collection easier, but whether one is worth it depends on your size and how your systems are set up.
Can you be our SOC 2 auditor?
No. SOC 2 reports must be issued by an independent licensed CPA firm. We prepare you for that audit.
Does SOC 2 cover HIPAA?
No, they are separate. Many of the same controls support both, so work done for one often helps with the other, but each has its own requirements.
Not sure if you need SOC 2 yet?
A short conversation can usually answer that. No pressure, no jargon.