In short: a SOC 2 report is an attestation by an independent CPA firm on your controls, measured against the AICPA's Trust Services Criteria. Security is always in scope; availability, processing integrity, confidentiality and privacy are added when relevant. Readiness means having the controls in place, and the evidence that they work, before the examination starts.
What SOC 2 is
The Trust Services Criteria are control criteria established by the AICPA's Assurance Services Executive Committee for attestation and consulting engagements. The current version is the 2017 Trust Services Criteria, with revised points of focus (2022). A SOC 2 examination reports on controls at a service organisation relevant to five categories: security, availability, processing integrity, confidentiality and privacy.
SOC reports are assurance reports issued by CPAs to help the users of a service assess the risks of relying on it. That is why customers ask for them: your SOC 2 report is how a CPA firm tells them what it found.
A report, not a certificate. CPA firms point out that "SOC 2 certification" is a misconception: SOC 2 is an attestation report, not a certification. ISO 27001, by contrast, is a certification. See SOC 2 vs ISO 27001.
What is always in scope
Security, the common criteria, is required in every SOC 2 report. The other four categories are included when they matter to the service you provide and to your customers.
Type 1 and Type 2
A Type 1 report looks at the design of your controls at a single point in time. A Type 2 report tests how the controls operated over a period, which auditors describe as typically 3 to 12 months. The details, and published fees for each, are in SOC 2 Type 1 vs Type 2.
What readiness work usually involves
The criteria describe what must be achieved, not how to prepare. In practice, preparation tends to move through these stages:
- Scope. Decide which services, systems and Trust Services Criteria categories the report will cover, beyond the required security criteria.
- Gap assessment. Compare what you do today against the criteria in scope. Our readiness assessment is a quick first pass.
- Remediation. Write the missing policies and put the missing controls in place: access reviews, joiner and leaver checks, change approvals, incident response, backups, vendor reviews.
- Evidence. Collect proof that controls operate (tickets, logs, reviews, training records) as the work happens. For a Type 2, this runs across the whole observation period.
- The examination. An independent CPA firm tests the controls and issues the report.
Some controls matter whatever report you are preparing for. CISA, for example, recommends multi-factor authentication because accounts protected by it are significantly less likely to be compromised.
What it costs
Published audit-fee ranges start in the thousands of dollars and vary widely with scope, company size and the firm. They are collected, attributed and dated in the Security Compliance Cost & Readiness Index.
Only a CPA firm can issue a SOC 2 report or form an opinion on your controls. Nothing on this page is audit or legal advice, and no checklist guarantees an outcome.