Skip to content

SOC 2

The audit report US buyers ask for. It is not a certification, and that difference matters.

What SOC 2 is

SOC 2 is an audit report defined by the AICPA, the US institute of certified public accountants. An external auditor examines your organisation's controls against the Trust Services Criteria and issues an opinion.

There is no SOC 2 certificate and no seal. There is a report, with an auditor's opinion, a date and a scope. Whoever asks for it reads it.

There are two types. Type I assesses the design of the controls at a point in time. Type II also assesses their operating effectiveness over a period. The one you are almost always asked for is Type II.

Who SOC 2 applies to

No sector by law. It applies when your customer requires it, and the customers who require it are mostly American:

  • B2B SaaS selling to US companies
  • Vendors handling customer data in the cloud
  • Anyone whose buyer runs a third-party risk programme

In Europe it usually surfaces when a company crosses the Atlantic, or when a European customer has a US parent.

What SOC 2 requires

Five Trust Services Criteria. Only the first is mandatory:

  • Security, always included. It is the common criterion
  • Availability, where your service commitment justifies it
  • Processing integrity
  • Confidentiality
  • Privacy

Adding criteria widens the report and the work. They are chosen for what your customer needs to see, not to complete the list.

A Type II also requires an observation period during which the controls have to be running and leaving a trail. That trail is the evidence, and collecting it at the end of the period does not work: if it did not exist when the control ran, it does not exist.

How SOC 2 is demonstrated

With the report issued by an independent audit firm. The report carries an issue date and a period covered, and in practice it expires: a buyer rarely accepts a Type II older than twelve months.

With Zerod

SOC 2 is earned during the period, not at the end. Zerod works the same way.

Activate SOC 2 and Zerod gives you the control register for the criteria you chose, generates the supporting documentation, and organises continuous evidence collection, so that by the time your observation period starts the trail is already being produced.

Frequently asked questions

Is SOC 2 a certification?

No. It is an audit report carrying an independent auditor's opinion. There is no certificate and no official seal, and anyone claiming to be "SOC 2 certified" is describing what they have incorrectly.

Type I or Type II?

Type I shows the controls are well designed today. Type II shows they worked over a period. If your buyer does not specify, assume they want Type II.

SOC 2 · Zerod