SOC 2
SOC 2 Type II audit report
What it is
SOC 2 is an audit report showing that your security controls exist and actually work. An independent CPA firm checks areas like access control, change management, monitoring and incident response against the AICPA's Trust Services Criteria. Type I looks at how the controls are designed at a single point in time. Type II checks that they operated over a period, usually three to twelve months, and Type II is the one enterprise buyers want.
It is the default proof of security when selling to US companies. Without it you'll answer long security questionnaires by hand, and some deals won't start.
What it takes
About 6–12 engineer-weeks to build in-house, or 3–6 using Vanta, Drata or Secureframe.
Plan for six to nine months end to end. The Type II observation window is the long pole, not the engineering.
Answer these first
- Sales: Which deals, by name, are waiting on SOC 2?
- Engineering: Which systems are in scope, and which do we deliberately leave out?
- Engineering: Who has production access today, and how is it granted?
- Security: Who owns compliance day to day?
- Finance: Type I first, or straight to Type II?
- Legal: Which audit firm, and when does the observation window start?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.