SOC 2, explained for teams getting ready

SOC 2 is an independent auditor's report on how your security controls are designed and how they operate. Here is what it covers, how the two report types differ, and where teams usually fall short.

Assess SOC 2 free

13 questions · about 10 min · no signup

Type
Attestation report
Issued by
A licensed CPA firm
Framework
AICPA Trust Services Criteria
Report types
Type I and Type II

This guide is growing. A fuller SOC 2 guide, with requirement-by-requirement detail and worked examples, is being written. Last updated 1st October 2026.

On this page
01

What is SOC 2?

SOC 2 is a reporting framework from the American Institute of Certified Public Accountants (AICPA). A licensed CPA firm examines the controls at a service organization and reports on them against the Trust Services Criteria.

It is an attestation, not a certification. There is no SOC 2 certificate: you receive a report, which you share with customers, usually under a non-disclosure agreement.

02

Who asks for SOC 2?

  • US enterprise customers, during vendor security reviews and procurement.
  • Customers of SaaS and cloud companies that store or process their data.
  • Investors and partners doing security due diligence.

No law requires SOC 2. Like ISO 27001, it becomes a requirement when customers ask for it.

03

The five Trust Services Criteria

Criterion

Security

Required?

Always

What it covers

Protection against unauthorised access, across governance, risk, access, operations and change

Criterion

Availability

Required?

Optional

What it covers

Uptime commitments, capacity, backup and disaster recovery

Criterion

Processing integrity

Required?

Optional

What it covers

Complete, accurate and timely processing

Criterion

Confidentiality

Required?

Optional

What it covers

Protection of information designated as confidential

Criterion

Privacy

Required?

Optional

What it covers

Collection, use, retention and disposal of personal information

Security, also called the Common Criteria (CC1 to CC9), is part of every SOC 2. You add the others based on what you promise your customers.

04

SOC 2 Type I vs Type II

What it tests

Type I

Whether controls are designed properly

Type II

Whether controls are designed properly and worked over time

Period covered

Type I

A single point in time

Type II

An observation period, usually 3 to 12 months

What buyers expect

Type I

Often accepted as a first step

Type II

The report most enterprise buyers ask for
05

How a SOC 2 audit works

  • Choose the scope: the systems in the report and the criteria beyond Security.
  • Readiness or gap assessment: compare your controls with the criteria.
  • Implement and document the missing controls.
  • For Type II, run the controls through the observation period so they produce evidence.
  • The CPA firm tests the controls and issues the report.
  • Repeat each year: a Type II report covers a fixed period, so customers expect a current one.
06

Where teams usually fall short

  • Access reviews not performed, or not evidenced, on schedule.
  • Offboarding that leaves accounts active.
  • Changes to production without documented approval and testing.
  • No inventory or risk review of critical vendors.
  • Security alerts that are generated but not monitored.
  • Policies that exist but were never acknowledged by staff.
07

What the free assessment covers

The free SwaSec SOC 2 assessment asks 13 questions across 11 domains and takes about 10 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.

  • CC1: Control Environment. Commitment to integrity, ethical values, board oversight, and organizational structure.
  • CC2: Communication and Information. Quality information generation, internal and external communication of control information.
  • CC3: Risk Assessment. Risk identification, analysis, and consideration of fraud and change.
  • CC4: Monitoring Activities. Ongoing monitoring and periodic evaluation of internal controls.
  • CC5: Control Activities. Selection and deployment of control activities that mitigate risks.
  • CC6: Logical and Physical Access. Access controls, authentication, and restriction of system access points.
  • CC7: System Operations. Detection, response, and recovery from security events and incidents.
  • CC8: Change Management. Controlled change management for infrastructure, data, software, and procedures.
  • CC9: Risk Mitigation. Vendor risk management and business partner risk mitigation.
  • A1: Availability. Additional criteria for availability commitments, redundancy, and disaster recovery.
  • C1: Confidentiality. Additional criteria for identification and protection of confidential information.

Start the SOC 2 assessment. It is a self-assessment, not an audit or a certification.

08

How SOC 2 overlaps with other frameworks

SOC 2 shares 9 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.

09

Frequently asked questions

Is SOC 2 a certification?

No. SOC 2 is an attestation report issued by a licensed CPA firm. There is no SOC 2 certificate, although the phrase is common.

Should I get SOC 2 Type I or Type II?

Many teams start with Type I so they have a report to share sooner, then move to Type II. Ask the customers requesting it which they will accept.

What is the difference between SOC 2 and ISO 27001?

SOC 2 is a report on how specific controls are designed and operate, common with US buyers. ISO 27001 is a certification of your whole information security management system, common internationally. Their controls overlap a great deal.

How often do I need a SOC 2 report?

A Type II report covers a fixed period, so most companies renew it every year to keep a current report available for customers.

What does the free SwaSec SOC 2 assessment cover?

13 questions across 11 domains, taking about 10 minutes, with no signup. It gives you a score for SOC 2, the gaps it found, and the clause, control or article each gap relates to.

10

Sources

This guide is general information, not legal advice. Last updated 1st October 2026.

The other frameworks