What is SOC 2 ?

7 min read

SOC 2 trust services criteria and audit timeline explained

SOC 2 is an attestation report written by an independent CPA firm about whether your security controls were designed properly and, in the Type II version, whether they actually operated over a period of months.

  • Glossary
  • Compliance

The short answer

SOC 2 is an auditing standard from the American Institute of Certified Public Accountants. You select which of the five trust services criteria apply, deploy controls against them, then a licensed CPA firm examines the evidence and issues an opinion. There is no certificate and no pass mark. What you get is a report that enterprise buyers read during due diligence.

The distinction that trips people up: nobody certifies you. A CPA firm attests to what it observed. That is why a clean report still contains exceptions, and why buyers read the auditor’s opinion rather than looking for a badge.

The five SOC 2 trust services criteria

Every SOC 2 report includes Security. The other four criteria are elective, and scope creep here is the single most common cause of a longer, costlier engagement. Add a category only when a buyer contract or a regulator actually asks for it.

CriterionStatusWhat it covers
SecurityMandatoryProtection against unauthorised access, the common criteria every report includes
AvailabilityElectiveUptime commitments, capacity planning, disaster recovery
ConfidentialityElectiveHandling of information designated confidential by contract
Processing integrityElectiveWhether processing is complete, valid, accurate and timely
PrivacyElectiveCollection, use, retention and disposal of personal information

The common criteria behind Security run from CC1 to CC9, covering control environment, communication, risk assessment, monitoring, logical access, change management and incident handling. Those nine sections are where the evidence work concentrates, and they are broken down in detail in the CC1 to CC9 controls guide.

Type I and Type II

Type IType II
Question answeredAre the controls designed appropriately?Did the controls operate effectively over time?
Evidence basisA single point in timeAn observation window, usually three to twelve months
Typical useAn interim signal while the window runsWhat enterprise procurement teams actually ask for
RepeatsOnce, rarely repeatedAnnually, with a bridge letter covering the gap between reports

Most teams skip Type I unless a live deal needs something to show this quarter. The Type I versus Type II decision guide covers when the interim report is worth the extra audit fee.

How long SOC 2 actually takes

The timeline is dominated by one thing you cannot compress: the observation window. Controls have to run for months before there is anything for an auditor to sample.

Readiness Controls deployed, gaps closed, VAPT completed Observation window Controls run and generate evidence. Three months at the shortest. Not compressible. CPA audit and report Independent firm samples evidence and issues an opinion Readiness is where speed is won or lost. The window and the audit are fixed.

With controls already deployed and evidence flowing automatically, roughly 115 days end to end is achievable: about a week to reach readiness including VAPT, then the three month evidence window, then around ten days of CPA fieldwork. Teams that start readiness from scratch and collect evidence by hand routinely spend six to nine months instead, almost all of it before the window even opens.

The auditor is not the platform

No software vendor can issue a SOC 2 report, and none can guarantee the outcome. A platform gets controls deployed and evidence organised. A licensed CPA firm performs the examination and forms the opinion. Anyone describing SOC 2 as something they certify has the relationship backwards.

What SOC 2 is not

AssumptionReality
It is a certificationIt is an attestation report containing an auditor’s opinion, not a certificate issued by a body
You pass or failReports carry an opinion, and exceptions can appear in a report that is still useful to buyers
There is a fixed control listCriteria are outcome-based, so two companies can meet the same criterion with different controls
It is legally requiredNo law mandates it. Buyers and contracts do, which is covered in is SOC 2 mandatory
One report lasts foreverType II reports cover a defined window and are repeated annually

Where it sits against ISO 27001

They overlap heavily in controls and differ completely in structure. ISO 27001 certifies a management system through an accredited certification body and is recognised globally. SOC 2 produces a report from a CPA firm and is what North American buyers ask for by name. Teams selling into both markets usually run one control set and map it twice, a pattern the SOC 2 versus ISO 27001 comparison works through.

The shared foundation is the same either way: a documented risk assessment, access control with MFA, encryption at rest, monitoring, and incident handling with records to prove each one ran.

How Osto gets you SOC 2 audit-ready

Most compliance platforms watch controls you bought elsewhere and collect the evidence. Osto deploys the controls itself, then produces the evidence from its own modules, which is why readiness takes days rather than months. Access control, endpoint, cloud posture, web and API protection, logging and VAPT all run in one stack, so a control and its evidence trail come from the same place.

Policies are generated in context rather than pulled from a template pack, security awareness training runs inside the platform, and the same control set maps across 200 or more frameworks including ISO 27001, HIPAA and the DPDP Act. Osto does not perform the audit. An independent CPA firm does that, and Osto makes sure there is nothing left to find when they arrive. Start with the readiness checklist or the founder’s guide.

Platform walkthrough

Readiness in days, not quarters

Osto deploys the controls and generates the evidence from its own modules, so the observation window starts sooner and the auditor finds nothing outstanding. One owner, one dashboard.

Book a demo

200+ frameworks mapped · Evidence from your own stack · One platform, everything

Frequently asked questions

What is SOC 2?

An auditing standard from the American Institute of Certified Public Accountants. An independent CPA firm examines your controls against selected trust services criteria and issues a report containing its opinion. Enterprise buyers request it during vendor due diligence.

Is SOC 2 a certification?

No. It is an attestation report, not a certificate. There is no certifying body and no badge. What exists is a report signed by a licensed CPA firm describing what it examined and what it concluded, which is why buyers read the report rather than checking for a logo.

What are the five trust services criteria?

Security, availability, confidentiality, processing integrity and privacy. Security is mandatory in every report. The other four are included only when a buyer, a contract or a regulator requires them, and each one added extends the engagement.

How long does SOC 2 take?

Around 115 days end to end when controls are already deployed and evidence is generated automatically: roughly a week to reach readiness including penetration testing, a three month minimum observation window, and about ten days of CPA fieldwork. Starting from nothing with manual evidence collection typically takes six to nine months.

Should I get Type I or Type II?

Type II, in almost every case, because that is what enterprise procurement asks for. Type I is worth the extra fee only when a live deal needs a signal before the observation window closes.

Is SOC 2 legally required?

No statute requires it anywhere. It becomes effectively mandatory through commercial pressure, when an enterprise customer makes it a condition of the contract or a security questionnaire asks for the report by name.