SOC 2 Compliance definition
SOC 2 compliance is the status of a service organization that has been examined by an independent CPA firm against the AICPA's Trust Services Criteria and holds a SOC 2 report describing its controls. The report covers security and, optionally, availability, processing integrity, confidentiality and privacy. It is widely requested by customers of SaaS and cloud service providers.
What does SOC 2 cover?
SOC 2 was developed by the American Institute of Certified Public Accountants (AICPA). It is an attestation, not a certification: a licensed CPA firm examines your controls and issues a report with its opinion. Each organization chooses which Trust Services Criteria are in scope based on the commitments it makes to customers. Security, also called the common criteria, is always included, and the other four categories are added when relevant to the service. Scope also defines which systems are examined.
- Security: protection against unauthorized access and system damage.
- Availability: systems are available for operation as committed.
- Processing integrity: processing is complete, accurate, timely and authorized.
- Confidentiality: information designated confidential is protected.
- Privacy: personal information is handled according to stated commitments.
SOC 2 Type I vs Type II
A Type I report evaluates whether controls are suitably designed and in place at a specific point in time. It can be obtained relatively quickly and is often a first step for young companies. A Type II report evaluates whether controls operated effectively over a period, commonly somewhere between three and twelve months, based on evidence such as access reviews, change tickets and incident records. Enterprise customers typically ask for Type II, because it shows controls actually work in practice.
Who needs SOC 2?
SOC 2 is not legally required. It is a market expectation, mainly for SaaS companies, cloud providers, data processors and other vendors that store or handle customer data, especially when selling to larger businesses in North America. Security questionnaires during sales often ask for a SOC 2 report first. Companies serving other regions may be asked for ISO/IEC 27001 certification instead, and many mature vendors maintain both, mapping one set of controls to both frameworks.
How to prepare for a SOC 2 audit
Start with a readiness assessment to define scope and compare current practices with the criteria. Typical gaps include missing written policies, inconsistent access reviews, no formal change management, weak vendor management, incomplete logging and untested incident response or backup restores. Compliance automation platforms such as Vanta, Drata and Secureframe can collect evidence from cloud and HR systems, but the controls themselves still need to be implemented and followed every day. Fix gaps before the observation period begins.
Choose an experienced CPA firm, agree the audit period for Type II, and treat the first report as the start of an ongoing program, since reports are typically renewed annually. Keep evidence collection continuous rather than scrambling before each audit window.
SOC 2 and engineering teams
Many SOC 2 controls live in engineering practice: code review, protected branches, CI/CD with approvals, infrastructure as code, least-privilege cloud access, encryption, monitoring and documented incident response. Nexzem helps SaaS clients build these controls into their platforms and delivery processes. This page is general information, not legal or audit advice; your CPA firm determines how criteria apply to your organization.