Mara logo

SOC 2

An audit report on how a service organisation handles customer data — the document that unblocks most enterprise software deals.

Industry & Domain

SOC 2 reports on controls against five trust services criteria — security, availability, processing integrity, confidentiality and privacy — of which security is mandatory and the rest optional. Type I assesses whether controls are designed appropriately at a point in time; Type II tests whether they operated effectively over a period, usually three to twelve months. Enterprise buyers almost always mean Type II.

It is not a certification and there is no pass mark: the output is an auditor's opinion plus any exceptions found. For a product team the practical consequences are concrete — audit logs with real retention, access controls and reviews, change management, incident response, and evidence that all of it happened rather than merely existed as policy.

It is a sales gate before it is a security improvement

Most companies pursue SOC 2 because a deal requires it. Starting when the deal appears means a Type II observation window measured in months while the buyer waits — which is why it is worth starting before the first enterprise prospect asks.

In practice

A Series A product was asked for SOC 2 Type II during procurement. They had good practices and no evidence trail, so the three-month observation window started from zero. The deal slipped two quarters; the competitor who already had the report signed in six weeks.

Where teams get it wrong

  • Starting only when a deal requires it, which adds months of observation window.
  • Treating it as a certification rather than an audit opinion with exceptions.
  • Writing policies without producing the evidence that they were followed.
  • Scoping only the security criterion when the buyer needs availability or confidentiality too.
  • Assuming a report from two years ago still satisfies a buyer.

Learn more

You may ask

Frequently Asked Questions

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether they operated effectively across a period, usually three to twelve months. Enterprise buyers generally require Type II.

Is SOC 2 a certification?

No. It is an independent auditor's report on controls, including any exceptions found. There is no pass or fail mark and no certificate — buyers read the report.

Related terms

All terms

Defined by Mara Last reviewed .

Let's talk about your product.

Happy to look at what you're building and say where design would move the needle.

Contact Us