{"id":1123,"date":"2026-09-09T12:05:02","date_gmt":"2026-09-09T12:05:02","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1123"},"modified":"2026-09-09T12:05:02","modified_gmt":"2026-09-09T12:05:02","slug":"soc-2","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/","title":{"rendered":"What is SOC 2 ?"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SOC 2\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">SOC 2 is an attestation report written by an independent CPA firm about whether your security controls were designed properly and, in the Type II version, whether they actually operated over a period of months.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>SOC 2 is an auditing standard from the American Institute of Certified Public Accountants. You select which of the five trust services criteria apply, deploy controls against them, then a licensed CPA firm examines the evidence and issues an opinion. There is no certificate and no pass mark. What you get is a report that enterprise buyers read during due diligence.<\/p>\n<\/div>\n\n<p>The distinction that trips people up: nobody certifies you. A CPA firm attests to what it observed. That is why a clean report still contains exceptions, and why buyers read the auditor&#8217;s opinion rather than looking for a badge.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#tsc\">The five SOC 2 trust services criteria<\/a><\/li>\n    <li><a href=\"#types\">Type I and Type II<\/a><\/li>\n    <li><a href=\"#timeline\">How long SOC 2 actually takes<\/a><\/li>\n    <li><a href=\"#not\">What SOC 2 is not<\/a><\/li>\n    <li><a href=\"#iso\">Where it sits against ISO 27001<\/a><\/li>\n    <li><a href=\"#osto\">How Osto gets you SOC 2 audit-ready<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"tsc\">The five SOC 2 trust services criteria<\/h2>\n\n<p>Every SOC 2 report includes Security. The other four criteria are elective, and scope creep here is the single most common cause of a longer, costlier engagement. Add a category only when a buyer contract or a regulator actually asks for it.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Criterion<\/th><th>Status<\/th><th>What it covers<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Security<\/strong><\/td><td><span class=\"pill p-req\">Mandatory<\/span><\/td><td>Protection against unauthorised access, the common criteria every report includes<\/td><\/tr>\n    <tr><td>Availability<\/td><td><span class=\"pill p-imp\">Elective<\/span><\/td><td>Uptime commitments, capacity planning, disaster recovery<\/td><\/tr>\n    <tr><td>Confidentiality<\/td><td><span class=\"pill p-imp\">Elective<\/span><\/td><td>Handling of information designated confidential by contract<\/td><\/tr>\n    <tr><td>Processing integrity<\/td><td><span class=\"pill p-imp\">Elective<\/span><\/td><td>Whether processing is complete, valid, accurate and timely<\/td><\/tr>\n    <tr><td>Privacy<\/td><td><span class=\"pill p-imp\">Elective<\/span><\/td><td>Collection, use, retention and disposal of personal information<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The common criteria behind Security run from CC1 to CC9, covering control environment, communication, risk assessment, monitoring, logical access, change management and incident handling. Those nine sections are where the evidence work concentrates, and they are broken down in detail in the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\">CC1 to CC9 controls guide<\/a>.<\/p>\n\n<h2 id=\"types\" class=\"c-sage\">Type I and Type II<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>Type I<\/th><th>Type II<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Question answered<\/td><td>Are the controls designed appropriately?<\/td><td>Did the controls operate effectively over time?<\/td><\/tr>\n    <tr><td>Evidence basis<\/td><td>A single point in time<\/td><td>An observation window, usually three to twelve months<\/td><\/tr>\n    <tr><td>Typical use<\/td><td>An interim signal while the window runs<\/td><td>What enterprise procurement teams actually ask for<\/td><\/tr>\n    <tr><td>Repeats<\/td><td>Once, rarely repeated<\/td><td>Annually, with a bridge letter covering the gap between reports<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Most teams skip Type I unless a live deal needs something to show this quarter. The <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-type-1-vs-type-2\/\">Type I versus Type II decision guide<\/a> covers when the interim report is worth the extra audit fee.<\/p>\n\n<h2 id=\"timeline\" class=\"c-apri\">How long SOC 2 actually takes<\/h2>\n\n<p>The timeline is dominated by one thing you cannot compress: the observation window. Controls have to run for months before there is anything for an auditor to sample.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 176\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SOC 2 timeline showing readiness, evidence window and CPA audit stages.\">\n  <defs><marker id=\"s2a\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"30\" width=\"176\" height=\"74\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"102\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Readiness<\/text>\n  <text x=\"102\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Controls deployed, gaps<\/text>\n  <text x=\"102\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">closed, VAPT completed<\/text>\n  <line x1=\"194\" y1=\"67\" x2=\"212\" y2=\"67\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#s2a)\"\/>\n\n  <rect x=\"218\" y=\"30\" width=\"284\" height=\"74\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"360\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Observation window<\/text>\n  <text x=\"360\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">Controls run and generate evidence.<\/text>\n  <text x=\"360\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">Three months at the shortest. Not compressible.<\/text>\n  <line x1=\"506\" y1=\"67\" x2=\"524\" y2=\"67\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#s2a)\"\/>\n\n  <rect x=\"530\" y=\"30\" width=\"216\" height=\"74\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"638\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">CPA audit and report<\/text>\n  <text x=\"638\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Independent firm samples<\/text>\n  <text x=\"638\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">evidence and issues an opinion<\/text>\n\n  <rect x=\"14\" y=\"118\" width=\"732\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"144\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Readiness is where speed is won or lost. The window and the audit are fixed.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>With controls already deployed and evidence flowing automatically, roughly 115 days end to end is achievable: about a week to reach readiness including <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a>, then the three month evidence window, then around ten days of CPA fieldwork. Teams that start readiness from scratch and collect evidence by hand routinely spend six to nine months instead, almost all of it before the window even opens.<\/p>\n\n<div class=\"callout\">\n  <p class=\"k\">The auditor is not the platform<\/p>\n  <p>No software vendor can issue a SOC 2 report, and none can guarantee the outcome. A platform gets controls deployed and evidence organised. A licensed CPA firm performs the examination and forms the opinion. Anyone describing SOC 2 as something they certify has the relationship backwards.<\/p>\n<\/div>\n\n<h2 id=\"not\" class=\"c-plum\">What SOC 2 is not<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Assumption<\/th><th>Reality<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>It is a certification<\/td><td>It is an attestation report containing an auditor&#8217;s opinion, not a certificate issued by a body<\/td><\/tr>\n    <tr><td>You pass or fail<\/td><td>Reports carry an opinion, and exceptions can appear in a report that is still useful to buyers<\/td><\/tr>\n    <tr><td>There is a fixed control list<\/td><td>Criteria are outcome-based, so two companies can meet the same criterion with different controls<\/td><\/tr>\n    <tr><td>It is legally required<\/td><td>No law mandates it. Buyers and contracts do, which is covered in <a href=\"https:\/\/www.osto.one\/resources\/blog\/is-soc-2-mandatory\/\">is SOC 2 mandatory<\/a><\/td><\/tr>\n    <tr><td>One report lasts forever<\/td><td>Type II reports cover a defined window and are repeated annually<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"iso\" class=\"c-sage\">Where it sits against ISO 27001<\/h2>\n\n<p>They overlap heavily in controls and differ completely in structure. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> certifies a management system through an accredited certification body and is recognised globally. SOC 2 produces a report from a CPA firm and is what North American buyers ask for by name. Teams selling into both markets usually run one control set and map it twice, a pattern the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-vs-iso-27001\/\">SOC 2 versus ISO 27001 comparison<\/a> works through.<\/p>\n\n<p>The shared foundation is the same either way: a documented <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a>, access control with <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption at rest<\/a>, monitoring, and incident handling with records to prove each one ran.<\/p>\n\n<h2 id=\"osto\">How Osto gets you SOC 2 audit-ready<\/h2>\n\n<p>Most compliance platforms watch controls you bought elsewhere and collect the evidence. Osto deploys the controls itself, then produces the evidence from its own modules, which is why readiness takes days rather than months. Access control, endpoint, cloud posture, web and API protection, logging and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> all run in one stack, so a control and its evidence trail come from the same place.<\/p>\n\n<p>Policies are generated in context rather than pulled from a template pack, security awareness training runs inside the platform, and the same control set maps across 200 or more frameworks including <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, HIPAA and the DPDP Act. Osto does not perform the audit. An independent CPA firm does that, and Osto makes sure there is nothing left to find when they arrive. Start with the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-readiness-checklist\/\">readiness checklist<\/a> or the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-for-startups\/\">founder&#8217;s guide<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Readiness in days, not quarters<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto deploys the controls and generates the evidence from its own modules, so the observation window starts sooner and the auditor finds nothing outstanding. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">200+ frameworks mapped &middot; Evidence from your own stack &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is SOC 2?<\/summary>\n  <p>An auditing standard from the American Institute of Certified Public Accountants. An independent CPA firm examines your controls against selected trust services criteria and issues a report containing its opinion. Enterprise buyers request it during vendor due diligence.<\/p>\n<\/details>\n\n<details>\n  <summary>Is SOC 2 a certification?<\/summary>\n  <p>No. It is an attestation report, not a certificate. There is no certifying body and no badge. What exists is a report signed by a licensed CPA firm describing what it examined and what it concluded, which is why buyers read the report rather than checking for a logo.<\/p>\n<\/details>\n\n<details>\n  <summary>What are the five trust services criteria?<\/summary>\n  <p>Security, availability, confidentiality, processing integrity and privacy. Security is mandatory in every report. The other four are included only when a buyer, a contract or a regulator requires them, and each one added extends the engagement.<\/p>\n<\/details>\n\n<details>\n  <summary>How long does SOC 2 take?<\/summary>\n  <p>Around 115 days end to end when controls are already deployed and evidence is generated automatically: roughly a week to reach readiness including penetration testing, a three month minimum observation window, and about ten days of CPA fieldwork. Starting from nothing with manual evidence collection typically takes six to nine months.<\/p>\n<\/details>\n\n<details>\n  <summary>Should I get Type I or Type II?<\/summary>\n  <p>Type II, in almost every case, because that is what enterprise procurement asks for. Type I is worth the extra fee only when a live deal needs a signal before the observation window closes.<\/p>\n<\/details>\n\n<details>\n  <summary>Is SOC 2 legally required?<\/summary>\n  <p>No statute requires it anywhere. It becomes effectively mandatory through commercial pressure, when an enterprise customer makes it a condition of the contract or a security questionnaire asks for the report by name.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A Controls<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at Rest<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SOC 2 is an attestation report written by an independent CPA firm about whether your security controls were designed properly\u2026<\/p>\n","protected":false},"author":8,"featured_media":1124,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[15,528,529],"class_list":["post-1123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-soc-2","tag-soc-2-compliance","tag-trust-services-criteria"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1123"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1123\/revisions"}],"predecessor-version":[{"id":1125,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1123\/revisions\/1125"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1124"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}