What Is SOC 2? Type I vs. Type II Explained

SOC 2 (System and Organization Controls 2): The Security Report Bigger Clients Ask For

SOC 2 is an independent audit report showing clients, partners and insurers how your organization protects their data, and whether those controls actually work. For companies that store or process data on someone else's behalf, it has become a standard request.

SOC 2 has become one of the most requested security credentials in business-to-business relationships. If you sell software, run a SaaS platform, provide managed IT services or handle sensitive data for other organizations, there's a good chance a prospect or large client has already asked for your SOC 2 report, or soon will.

What does SOC 2 stand for?

System and Organization Controls 2. SOC 2 was developed by the American Institute of Certified Public Accountants (AICPA), the same body behind financial auditing standards. It is designed for service organizations: companies that provide services involving customer data, rather than just selling a product.

There is also SOC 1 (focused on controls relevant to clients' financial reporting) and SOC 3 (a shorter, public summary of a SOC 2 examination). When people say "SOC 2" without qualification, they usually mean a SOC 2 Type II report.

The simple way to think about it

A SOC 2 report is an independent CPA firm's opinion on whether your security controls are designed well and, for Type II, whether they operated effectively over time. Think of it as a security background check performed on behalf of your customers.

Unlike HIPAA or GLBA, SOC 2 is not a law. It is voluntary, but market pressure has made it close to mandatory in many industries. Larger companies, healthcare organizations and financial institutions often ask for a SOC 2 report before signing a vendor agreement.

Type I vs. Type II

SOC 2 Type I looks at a single point in time. The auditor evaluates whether your controls are suitably designed as of a specific date. It is faster and cheaper, and it is sometimes used as a stepping stone toward Type II.

SOC 2 Type II covers a period of time, commonly 6 to 12 months. The auditor tests whether your controls operated effectively throughout that period. This is what most sophisticated buyers want, and security-minded procurement teams often treat a Type I report as a starting point rather than an answer.

The five Trust Services Criteria

SOC 2 is built around the AICPA's Trust Services Criteria (TSC). There are five categories:

  • Security (always included): protection of systems and data against unauthorized access. Every SOC 2 report covers it.
  • Availability (optional): systems are available for operation and use as committed. Relevant for SaaS and cloud services with uptime commitments.
  • Processing integrity (optional): processing is complete, valid, accurate, timely and authorized. Relevant for financial processing and data pipelines.
  • Confidentiality (optional): information designated as confidential is protected. Relevant for proprietary business data and NDA-covered information.
  • Privacy (optional): personal information is collected, used, retained and disposed of in line with your privacy notice and commitments.

Most organizations start with Security only and add criteria as client requirements grow.

What SOC 2 actually asks you to do

SOC 2 doesn't prescribe specific technologies. It evaluates whether your controls meet the criteria, which gives you flexibility but still means real work: you have to build, document and consistently operate the controls, then let an auditor test them.

Controls commonly examined in a SOC 2 audit include:

  • Access management and least-privilege permissions
  • Multi-factor authentication (MFA)
  • Encryption at rest and in transit
  • Vulnerability management and patching
  • Security monitoring and alerting
  • Incident response procedures
  • Vendor and third-party risk management
  • Security awareness training and background checks
  • Change management
  • Physical security of offices and data centers
  • Business continuity and disaster recovery planning

The resulting report describes your system and controls, the auditor's tests and the results. It is the document you share, usually under NDA, with clients and prospects who ask for SOC 2 evidence.

How long does SOC 2 take?

Getting to a SOC 2 Type II report is a project, not a purchase. A typical path looks like this:

  • Readiness assessment: often one to three months to find the gaps between your current controls and the criteria
  • Remediation: anywhere from weeks to many months, depending on how much needs to be built or documented
  • Observation period: commonly 6 to 12 months of operating the controls
  • Audit fieldwork and report: often one to three months

Starting from scratch, a year or more to a Type II report is common. A Type I report can come sooner because it has no observation period.

How SOC 2 connects to managed IT services

Many of the controls SOC 2 auditors test are IT infrastructure controls, so the way your IT is run directly affects your audit readiness. A Managed Service Provider (MSP) contributes through:

  • Endpoint protection, including EDR, which auditors review under the Security criterion
  • Patch management through RMM, with evidence of consistent, timely patching
  • Access controls and MFA across systems
  • Logging and monitoring, a core source of audit evidence
  • Backup and disaster recovery, especially if Availability is in scope
  • Vendor documentation, because your IT provider is itself a vendor your auditor will ask about

If you run on a cloud platform such as Microsoft Azure, AWS or Google Cloud, that provider's own SOC 2 report becomes part of your story. You inherit some controls from them, and your auditor will want to see their report.

NerdSquad helps companies get their IT controls and documentation ready for a SOC 2 audit and keeps those controls running during the observation period. The audit opinion itself comes from an independent CPA firm. See our managed IT services for how that support fits into day-to-day IT.

How SOC 2 fits with other frameworks

  • NIST Cybersecurity Framework: the AICPA publishes mappings between the Trust Services Criteria and NIST CSF, so a NIST-based security program makes SOC 2 preparation easier.
  • HIPAA: shares many technical controls with SOC 2; healthcare technology companies often pursue both.
  • GLBA: Safeguards Rule requirements line up closely with the Security criterion, so financial services firms can often support both with one control environment.
  • ISO 27001: often compared to SOC 2. ISO 27001 is a certifiable standard for an information security management system, while SOC 2 is an attestation report. Companies with international clients sometimes pursue both.

Quick reference

  • SOC 2: an independent attestation on a service organization's controls.
  • AICPA: the body that maintains the framework.
  • Type I: design at a point in time. Type II: operating effectiveness over a period.
  • Trust Services Criteria: Security (always), plus optional Availability, Processing Integrity, Confidentiality and Privacy.
  • Not a law: voluntary, but often required by clients.
  • The report: shared with clients under NDA; SOC 3 is the public version.

Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses