Skip to content
Compliance Framework

SOC 2

SOC 2 reports on how a service organization controls customer data against the Trust Services Criteria. A Type I report covers how controls are designed at a point in time; a Type II covers how they operated over a period. Enterprise buyers routinely ask for one before they sign.

Compliance Guide
7 min read

What SOC 2 is

SOC 2 is an attestation report produced by an independent CPA firm on how a service organization controls customer data. It is examined against the Trust Services Criteria, and the output is an opinion, not a certificate.

It has become the default answer to a security questionnaire in commercial software. When an enterprise buyer, a procurement team, or a partner asks how you protect their data, a SOC 2 report is what they usually expect to receive instead of a hundred separate answers.

Type I and Type II

The two report types answer different questions, and buyers rarely treat them as interchangeable.

  • A Type I report covers whether controls are suitably designed as of a single date. It is a snapshot, and it can be produced relatively quickly.
  • A Type II report covers whether those controls operated effectively across a period, typically three to twelve months. It requires evidence from throughout that window.
  • Most enterprise buyers want a Type II. A Type I is commonly used as a first step while the observation period for the Type II accrues.

The Trust Services Criteria

Every SOC 2 engagement covers Security, referred to as the common criteria. The remaining four categories are included only if they are relevant to what you provide and what you are willing to be examined on.

  • Security: protection against unauthorized access, disclosure, and damage. Always in scope.
  • Availability: the system is available for operation and use as committed
  • Processing Integrity: processing is complete, valid, accurate, timely, and authorized
  • Confidentiality: information designated confidential is protected as committed
  • Privacy: personal information is collected, used, retained, and disposed of as committed

What an engagement actually involves

The audit itself is the short part. Most of the work happens before the auditor arrives and continues through the observation period.

  • Defining the system description and the boundary of what is being examined
  • Selecting the criteria in scope and mapping your controls to each one
  • Closing the gaps readiness surfaces, which is usually where the real effort sits
  • Producing evidence continuously through the observation window, not reconstructing it at the end
  • Managing the auditor’s sample requests and responding to exceptions as they are raised
  • Tracking any exceptions that make it into the final report and what you did about them

Why it does not stay finished

A SOC 2 report covers a stated period and then expires in the eyes of the people reading it. Buyers ask for a current one, which means the observation period has to run continuously rather than being restarted each year from a standing stop.

That is the part organizations tend to underestimate. Evidence has to accumulate all year for controls that operate all year, and a control that quietly stopped running in month four becomes an exception in the report that a buyer will read.

How Verdict helps

Verdict runs the readiness work, maintains the system description and control mapping, and keeps the evidence record accumulating through the observation period so the audit is a review rather than a scramble.

We manage the auditor relationship through fieldwork and carry the remediation record for anything raised. You review all of it in a client portal: what is covered, what evidence sits behind each control, what is open, and what changed.

One boundary worth stating plainly: Verdict is not your auditor. The opinion has to come from an independent CPA firm, and we do the work that gets you a clean one.

SOC 2 is part of commercial assurance, the work that covers what a customer, partner, or procurement team asks you to produce before they will do business with you. The same lane also covers ISO/IEC 27001, and HIPAA. For the mechanics of an engagement, see how we work.

Whether you are working toward a first Type I or maintaining an annual Type II, we can run the readiness work and hold the record through the audit.

Talk to a Consultant