Threat ResQ

Compliance

SOC 2: The Complete Guide to Trust Services Criteria and Compliance

SOC 2 (System and Organization Controls 2) is an attestation framework developed by the AICPA that evaluates how a service organization manages customer data, based on five Trust Services Criteria. Unlike a certification

8 min readLast reviewed September 3, 2026Threat ResQ Technologies

SOC 2: The Complete Guide to Trust Services Criteria and Compliance

Executive Summary

SOC 2 (System and Organization Controls 2) is an attestation framework developed by the AICPA that evaluates how a service organization manages customer data, based on five Trust Services Criteria. Unlike a certification, SOC 2 results in an independent auditor's report — issued only by a licensed CPA firm — describing the organization's controls and, for a Type II report, testing whether those controls actually operated effectively over a period of time. This guide covers the Trust Services Criteria, the difference between Type I and Type II reports, how the audit process works, and how getTRAC automates the evidence collection a SOC 2 program depends on.

Key Takeaways

  • SOC 2 is an attestation, not a certification — the deliverable is an auditor's report, issued by a licensed CPA firm, not a certificate.
  • There are five Trust Services Criteria: Security (required for every report), Availability, Processing Integrity, Confidentiality, and Privacy — an organization scopes in the categories relevant to its service.
  • A Type I report assesses whether controls are suitably designed at a single point in time; a Type II report tests whether those controls operated effectively over a period, typically 3–12 months.
  • SOC 2 reports are shared under NDA with customers and prospects, not published publicly like an ISO certificate.
  • SOC 2 is the dominant trust framework for SaaS companies selling into the US market, and increasingly requested globally.

What SOC 2 actually evaluates {#what-it-evaluates}

SOC 2 evaluates a service organization's controls relevant to the security, availability, processing integrity, confidentiality, or privacy of the systems it uses to process customer data. It's built specifically for technology and service companies — SaaS platforms, data processors, cloud infrastructure providers — where customers need assurance about how their data is protected without direct visibility into the provider's internal operations. The report itself is produced by an independent, licensed CPA firm following AICPA attestation standards, not by the organization being assessed.

The five Trust Services Criteria {#trust-criteria}

  • Security — protection against unauthorized access, both physical and logical. This category is mandatory in every SOC 2 report.
  • Availability — the system is available for operation and use as committed or agreed.
  • Processing Integrity — system processing is complete, valid, accurate, timely, and authorized.
  • Confidentiality — information designated as confidential is protected as committed or agreed.
  • Privacy — personal information is collected, used, retained, disclosed, and disposed of in conformity with the organization's privacy notice.

Most organizations scope their first SOC 2 report to Security alone, then expand to additional criteria (commonly Availability and Confidentiality) as customer requirements grow.

Type I vs Type II reports {#type-i-vs-ii}

  • Type I — assesses whether controls are suitably designed and in place as of a specific date. Faster to obtain, often used as a first milestone.
  • Type II — assesses whether those same controls actually operated effectively over an observation period, typically 3 to 12 months. This is what most enterprise customers and vendor security reviews actually expect to see, since it demonstrates sustained operation rather than a design snapshot.

The audit process {#audit-process}

  1. Scoping — selecting which Trust Services Criteria apply to the service being assessed.
  2. Readiness assessment (gap analysis) — comparing current controls against the selected criteria before the formal audit begins.
  3. Remediation — closing identified gaps and building out any missing evidence-generation processes.
  4. Observation period (Type II only) — the controls operate, and evidence accumulates, over the chosen window.
  5. Fieldwork — the CPA firm tests the controls and evidence directly.
  6. Report issuance — the auditor issues the SOC 2 report, which is then shared with customers and prospects under NDA, not published publicly.

Who needs SOC 2 {#who-needs-it}

SOC 2 is effectively the default trust framework SaaS companies are asked for in enterprise sales cycles and vendor security reviews, particularly in the US market. It's common for a growing SaaS vendor to start with a Type I report to unblock early enterprise deals, then move to Type II as customer expectations mature.

Common implementation mistakes {#common-mistakes}

  • Starting the observation period before controls are actually stable — a Type II window with early gaps or exceptions is harder to explain than starting the clock once the control environment is genuinely ready.
  • Treating it as a point-in-time project instead of an ongoing program — SOC 2 reports typically need to be refreshed annually; controls that quietly drift between audits are the most common source of findings.
  • Under-scoping evidence generation — controls that exist but don't produce a reviewable evidence trail (access reviews that happen informally, logging that isn't retained) are difficult to test during fieldwork.
  • Confusing SOC 2 with a certification — there's no pass/fail certificate; the deliverable is a report, and a report with noted exceptions is still a valid SOC 2 report, just one that discloses those exceptions.

How getTRAC helps with SOC 2 {#how-gettrac-helps}

getTRAC maps ongoing platform activity to the SOC 2 Trust Services Criteria alongside seven other frameworks (ISO 27001, GDPR, DPDP, HIPAA, RBI, NIST, PCI DSS), generating the continuous evidence trail a Type II observation period actually requires — rather than reconstructing months of evidence retroactively before fieldwork begins. For organizations preparing for a first SOC 2 report, Compliance Consulting pairs a human consultant with the platform to run the readiness assessment and scoping work.

FAQ {#faq}

Is SOC 2 a certification? No — SOC 2 results in an attestation report issued by a licensed CPA firm, not a certificate. There's no accreditation body or pass/fail badge the way there is with ISO 27001.

Do I need SOC 2 Type I or Type II? Most enterprise customers and vendor security reviews expect Type II, since it demonstrates sustained operation rather than a design snapshot. Type I is commonly used as a faster first milestone when a deal is time-sensitive.

How long does a SOC 2 Type II observation period last? Typically 3 to 12 months, chosen by the organization — a first report is often shorter (e.g. 3–6 months) to get a report in hand faster, with subsequent annual reports covering a full 12-month period.

Can Threat ResQ issue our SOC 2 report? No — a SOC 2 report must be issued by an independent, licensed CPA firm. Threat ResQ's role is helping organizations prepare for the audit and maintain compliance evidence, not performing the attestation itself.

Frequently asked questions

Is SOC 2 a certification?

No — SOC 2 results in an attestation report issued by a licensed CPA firm, not a certificate. There's no accreditation body or pass/fail badge the way there is with ISO 27001.

Do I need SOC 2 Type I or Type II?

Most enterprise customers and vendor security reviews expect Type II, since it demonstrates sustained operation rather than a design snapshot. Type I is commonly used as a faster first milestone when a deal is time-sensitive.

How long does a SOC 2 Type II observation period last?

Typically 3 to 12 months, chosen by the organization — a first report is often shorter (e.g. 3–6 months) to get a report in hand faster, with subsequent annual reports covering a full 12-month period.

Ask TIARA about this article

Get a grounded answer on SOC 2 compliance, or ask your own question.

Talk to an Expert

We use cookies for essential function and, with consent, analytics. Cookie Policy