SOC 2 is an attestation report written by an independent CPA firm about whether your security controls were designed properly and, in the Type II version, whether they actually operated over a period of months.
The short answer
SOC 2 is an auditing standard from the American Institute of Certified Public Accountants. You select which of the five trust services criteria apply, deploy controls against them, then a licensed CPA firm examines the evidence and issues an opinion. There is no certificate and no pass mark. What you get is a report that enterprise buyers read during due diligence.
The distinction that trips people up: nobody certifies you. A CPA firm attests to what it observed. That is why a clean report still contains exceptions, and why buyers read the auditor’s opinion rather than looking for a badge.
On this page
The five SOC 2 trust services criteria
Every SOC 2 report includes Security. The other four criteria are elective, and scope creep here is the single most common cause of a longer, costlier engagement. Add a category only when a buyer contract or a regulator actually asks for it.
| Criterion | Status | What it covers |
|---|---|---|
| Security | Mandatory | Protection against unauthorised access, the common criteria every report includes |
| Availability | Elective | Uptime commitments, capacity planning, disaster recovery |
| Confidentiality | Elective | Handling of information designated confidential by contract |
| Processing integrity | Elective | Whether processing is complete, valid, accurate and timely |
| Privacy | Elective | Collection, use, retention and disposal of personal information |
The common criteria behind Security run from CC1 to CC9, covering control environment, communication, risk assessment, monitoring, logical access, change management and incident handling. Those nine sections are where the evidence work concentrates, and they are broken down in detail in the CC1 to CC9 controls guide.
Type I and Type II
| Type I | Type II | |
|---|---|---|
| Question answered | Are the controls designed appropriately? | Did the controls operate effectively over time? |
| Evidence basis | A single point in time | An observation window, usually three to twelve months |
| Typical use | An interim signal while the window runs | What enterprise procurement teams actually ask for |
| Repeats | Once, rarely repeated | Annually, with a bridge letter covering the gap between reports |
Most teams skip Type I unless a live deal needs something to show this quarter. The Type I versus Type II decision guide covers when the interim report is worth the extra audit fee.
How long SOC 2 actually takes
The timeline is dominated by one thing you cannot compress: the observation window. Controls have to run for months before there is anything for an auditor to sample.
With controls already deployed and evidence flowing automatically, roughly 115 days end to end is achievable: about a week to reach readiness including VAPT, then the three month evidence window, then around ten days of CPA fieldwork. Teams that start readiness from scratch and collect evidence by hand routinely spend six to nine months instead, almost all of it before the window even opens.
The auditor is not the platform
No software vendor can issue a SOC 2 report, and none can guarantee the outcome. A platform gets controls deployed and evidence organised. A licensed CPA firm performs the examination and forms the opinion. Anyone describing SOC 2 as something they certify has the relationship backwards.
What SOC 2 is not
| Assumption | Reality |
|---|---|
| It is a certification | It is an attestation report containing an auditor’s opinion, not a certificate issued by a body |
| You pass or fail | Reports carry an opinion, and exceptions can appear in a report that is still useful to buyers |
| There is a fixed control list | Criteria are outcome-based, so two companies can meet the same criterion with different controls |
| It is legally required | No law mandates it. Buyers and contracts do, which is covered in is SOC 2 mandatory |
| One report lasts forever | Type II reports cover a defined window and are repeated annually |
Where it sits against ISO 27001
They overlap heavily in controls and differ completely in structure. ISO 27001 certifies a management system through an accredited certification body and is recognised globally. SOC 2 produces a report from a CPA firm and is what North American buyers ask for by name. Teams selling into both markets usually run one control set and map it twice, a pattern the SOC 2 versus ISO 27001 comparison works through.
The shared foundation is the same either way: a documented risk assessment, access control with MFA, encryption at rest, monitoring, and incident handling with records to prove each one ran.
How Osto gets you SOC 2 audit-ready
Most compliance platforms watch controls you bought elsewhere and collect the evidence. Osto deploys the controls itself, then produces the evidence from its own modules, which is why readiness takes days rather than months. Access control, endpoint, cloud posture, web and API protection, logging and VAPT all run in one stack, so a control and its evidence trail come from the same place.
Policies are generated in context rather than pulled from a template pack, security awareness training runs inside the platform, and the same control set maps across 200 or more frameworks including ISO 27001, HIPAA and the DPDP Act. Osto does not perform the audit. An independent CPA firm does that, and Osto makes sure there is nothing left to find when they arrive. Start with the readiness checklist or the founder’s guide.
Platform walkthrough
Readiness in days, not quarters
Osto deploys the controls and generates the evidence from its own modules, so the observation window starts sooner and the auditor finds nothing outstanding. One owner, one dashboard.
Book a demo200+ frameworks mapped · Evidence from your own stack · One platform, everything
Frequently asked questions
What is SOC 2?
An auditing standard from the American Institute of Certified Public Accountants. An independent CPA firm examines your controls against selected trust services criteria and issues a report containing its opinion. Enterprise buyers request it during vendor due diligence.
Is SOC 2 a certification?
No. It is an attestation report, not a certificate. There is no certifying body and no badge. What exists is a report signed by a licensed CPA firm describing what it examined and what it concluded, which is why buyers read the report rather than checking for a logo.
What are the five trust services criteria?
Security, availability, confidentiality, processing integrity and privacy. Security is mandatory in every report. The other four are included only when a buyer, a contract or a regulator requires them, and each one added extends the engagement.
How long does SOC 2 take?
Around 115 days end to end when controls are already deployed and evidence is generated automatically: roughly a week to reach readiness including penetration testing, a three month minimum observation window, and about ten days of CPA fieldwork. Starting from nothing with manual evidence collection typically takes six to nine months.
Should I get Type I or Type II?
Type II, in almost every case, because that is what enterprise procurement asks for. Type I is worth the extra fee only when a live deal needs a signal before the observation window closes.
Is SOC 2 legally required?
No statute requires it anywhere. It becomes effectively mandatory through commercial pressure, when an enterprise customer makes it a condition of the contract or a security questionnaire asks for the report by name.