SOC 2
An audit report on how a service organisation handles customer data — the document that unblocks most enterprise software deals.
Industry & DomainSOC 2 reports on controls against five trust services criteria — security, availability, processing integrity, confidentiality and privacy — of which security is mandatory and the rest optional. Type I assesses whether controls are designed appropriately at a point in time; Type II tests whether they operated effectively over a period, usually three to twelve months. Enterprise buyers almost always mean Type II.
It is not a certification and there is no pass mark: the output is an auditor's opinion plus any exceptions found. For a product team the practical consequences are concrete — audit logs with real retention, access controls and reviews, change management, incident response, and evidence that all of it happened rather than merely existed as policy.
It is a sales gate before it is a security improvement
Most companies pursue SOC 2 because a deal requires it. Starting when the deal appears means a Type II observation window measured in months while the buyer waits — which is why it is worth starting before the first enterprise prospect asks.
In practice
A Series A product was asked for SOC 2 Type II during procurement. They had good practices and no evidence trail, so the three-month observation window started from zero. The deal slipped two quarters; the competitor who already had the report signed in six weeks.
Where teams get it wrong
- Starting only when a deal requires it, which adds months of observation window.
- Treating it as a certification rather than an audit opinion with exceptions.
- Writing policies without producing the evidence that they were followed.
- Scoping only the security criterion when the buyer needs availability or confidentiality too.
- Assuming a report from two years ago still satisfies a buyer.
Learn more
You may ask
Frequently Asked Questions
What is the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether they operated effectively across a period, usually three to twelve months. Enterprise buyers generally require Type II.
Is SOC 2 a certification?
No. It is an independent auditor's report on controls, including any exceptions found. There is no pass or fail mark and no certificate — buyers read the report.
Related terms
All terms- Audit LogAn immutable record of who did what and when — required by enterprise buyers and compliance frameworks, and usually built as an afterthought.
- Customer PortalAn authenticated area where customers handle their own account — the cheapest support channel a business has, when it covers the right things.
- Multi-TenancyOne application instance serving many customers with their data isolated from each other — the architecture nearly every SaaS product runs on.
- VPATThe Voluntary Product Accessibility Template — the document enterprise procurement asks for before a deal closes.
Defined by Mara Last reviewed .
Let's talk about your product.
Happy to look at what you're building and say where design would move the needle.
Contact Us