What Is SOC 2?
A quick guide to the report enterprise buyers actually ask for.
SOC 2 (System and Organization Controls 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It is not a certification in the ISO sense – there is no certificate and no accreditation body. Instead, a licensed CPA firm examines an organisation’s controls and issues a formal report containing its professional opinion.

| That report measures how well an organisation’s controls protect customer data against a defined set of criteria, rather than a fixed checklist – which is what makes SOC 2 flexible across very different businesses. | THE FIVE TRUST SERVICES CRITERIA
|
SOC & ITGC SIMPLIFIED, CLICK ON TO THE BELOW VIDEO TO CHECK OUT:
Only Security is mandatory; the other four are added based on what an organisation’s customers actually need assurance about. A payroll platform might add Confidentiality and Privacy; an infrastructure provider might prioritise Availability and Processing Integrity instead.
SOC 2 reports come in two forms – Type I and Type II – which differ in how long the auditor observes the controls for. That distinction matters enough that it’s worth its own explanation.
Related reading: SOC 2 Type 1 vs Type 2 · Who Needs SOC 2? · SOC 2 vs ISO 27001
How GCAI helps: GCAI runs a readiness assessment against the Trust Services Criteria before you ever speak to an auditor, so you walk into the engagement already knowing where the gaps are.
SOC 2 Type 1 vs Type 2: What’s the Difference?
Same criteria, same controls – the difference is what the auditor actually tests.
Every SOC 2 report is assessed against the same Trust Services Criteria and the same set of controls. The difference between a Type I and a Type II report isn’t what’s being checked – it’s how long the auditor watches it for.
A Type I report answers one question: are the controls suitably designed as of a specific date? It’s a snapshot. A Type II report goes further, testing whether those same controls operated effectively over an observation period of three to twelve months – a track record, not a photo.

| Type I | Type II | |
|---|---|---|
| Question answered | Are controls designed correctly? | Did controls operate effectively over time? |
| Timeframe | A single point in time | An observation period of 3-12 months |
| Typical total time | 5 weeks to 2 months | 6 to 15 months for a first report |
| Best for | A fast first step or urgent customer request | Enterprise procurement, renewals, mature programmes |
| Many organisations complete a Type I first to unblock an immediate deal, then move straight into the Type II observation period rather than running the two as separate projects. | WHICH ONE DO BUYERS WANT?
|
Related reading: What Is SOC 2? · The SOC 2 Audit Process · SOC 2 FAQ
How GCAI helps: GCAI helps you decide which report to start with based on your sales pipeline and current control maturity, so you don’t pay for a Type II observation period before you’re ready for one.
Who Needs SOC 2?
There’s no legal requirement – but for some businesses, it’s effectively a cost of doing business.
SOC 2 applies to any service organisation that stores, processes, or transmits customer data. It’s especially expected, almost by default, in a handful of sectors:
SaaS and cloud service providers. SOC 2 has effectively become table stakes for selling software to enterprise customers in North America – many procurement teams won’t proceed past a security review without a current report.
Fintech and financial services. Alongside regulations such as GLBA, SOC 2 reassures investors, partners, and customers that systems handling financial data are resilient and well controlled.
Healthcare technology. HIPAA governs how patient data must be protected, but it doesn’t include an independent audit. Healthcare SaaS vendors often pursue SOC 2 alongside HIPAA to show controls actually work, not just that a policy exists.
Managed service providers, HR tech, and payroll. Any business handling client systems, employee records, or confidential files faces the same expectations from the organisations that rely on them.
| If you’re not sure whether you need it yet, a few quick questions usually settle it: | DO YOU NEED SOC 2?
|

Early-stage companies can absolutely get a SOC 2 report – many pursue one specifically to unblock enterprise sales, starting with a Type I report while a longer Type II observation period runs in parallel.
Related reading: What Is SOC 2? · SOC 2 Type 1 vs Type 2 · The SOC 2 Audit Process
How GCAI helps: GCAI scopes your SOC 2 around what your actual customers are asking for, instead of defaulting to all five Trust Services Criteria and adding unnecessary audit time and cost.
SOC 2 vs ISO 27001: Which Do You Need?
Two well-respected frameworks with about 80% control overlap – and one easy way to decide.
SOC 2 and ISO 27001 are often treated as interchangeable because they cover similar ground – both evaluate how well an organisation protects data, and both involve an independent third-party assessment. But they differ in output, audience, and who’s allowed to perform the assessment.
| SOC 2 | ISO 27001 | |
|---|---|---|
| What you get | An attestation report (auditor’s opinion) | A formal certificate |
| Who performs it | A licensed CPA firm | An accredited certification body |
| Governing body | AICPA (USA) | ISO and IEC (international) |
| Scope | Selected Trust Services Criteria | A full information security management system |
| Strongest recognition | North America | Internationally, especially Europe |
| Validity / cycle | Considered current for ~12 months; annual renewal | Valid 3 years, with annual surveillance audits |
The quickest way to decide is to look at who’s asking. US-based SaaS buyers tend to ask for SOC 2 by name; international customers, especially in Europe, more often expect ISO 27001. Many organisations selling into both markets eventually pursue both, leaning on the roughly 80% control overlap between them to avoid duplicating the work.
It’s also worth distinguishing SOC 2 from its lesser-known sibling, SOC 1. SOC 1 covers controls relevant to a client’s financial reporting – built for payroll processors and billing platforms – while SOC 2 covers security, availability, processing integrity, confidentiality, and privacy, and applies far more broadly to organisations handling customer data.
Related reading: What Is SOC 2? · Who Needs SOC 2? · SOC 2 FAQ
How GCAI helps: GCAI supports both tracks – SOC 2 readiness alongside your CPA firm, and ISO 27001 certification through our accredited Lead Auditors – so a dual-compliance roadmap can be planned as one project instead of two.
The SOC 2 Audit Process
What a first-time engagement actually looks like, phase by phase.
A first-time SOC 2 Type II report typically moves through the same sequence of phases, though the length of each varies with how prepared an organisation already is going in:
| Phase | What happens | Typical duration |
|---|---|---|
| Readiness assessment | Gap analysis against the chosen Trust Services Criteria | 2-6 weeks |
| Remediation | Close identified gaps; implement and document controls | 1-3 months |
| Type I audit (optional) | Point-in-time review of control design | 2-5 weeks |
| Type II observation period | Controls operate continuously; evidence accumulates | 3-12 months |
| Type II fieldwork | Auditor samples evidence from across the observation window | 2-5 weeks |
| Report issued | Final SOC 2 report delivered to management | 2-6 weeks |
| Renewal | A new observation period begins to keep the report current | Annually |

| A first Type II report usually takes six to fifteen months end to end, with the observation period itself accounting for most of that. Renewals move faster once the evidence habits are already in place. | SOC 2 BY THE NUMBERS
|
The most common cause of delay isn’t the audit itself – it’s underestimating how much of the observation period requires controls to be followed consistently, not just documented. Access reviews, change approvals, and incident logs all need to happen on schedule throughout the window, because that’s exactly what the auditor samples.
Related reading: SOC 2 Type 1 vs Type 2 · Who Needs SOC 2? · SOC 2 FAQ
How GCAI helps: GCAI provides evidence-collection support throughout the observation period itself, not just at the readiness stage, so nothing falls through the cracks between fieldwork visits.
SOC 2 FAQ
The questions that come up most once the basics are out of the way.
Is SOC 2 a certification? No. SOC 2 produces an attestation report containing the auditor’s opinion, not a certificate. There is no accreditation body and no certificate to display, though many organisations still describe themselves informally as “SOC 2 compliant.”
Who is allowed to perform a SOC 2 audit? Only a licensed CPA firm in the US (or an equivalent professional body elsewhere, such as the ICAEW in the UK) can perform the engagement and sign the report. Readiness platforms and consultants can help prepare for the audit, but they cannot issue the report itself.
What happens if the auditor finds exceptions? Minor exceptions are typically noted in the report alongside management’s response, without preventing issuance. Significant control failures can lead to a qualified opinion, where the auditor states that one or more controls did not operate effectively – less severe than failing outright, but it does affect how the report is received by buyers.
Can we share our SOC 2 report publicly, like a badge on our website? A SOC 2 report itself is restricted-use – typically shared under NDA with prospects and customers performing due diligence, not posted publicly. Organisations that want a public-facing summary can have their auditor issue a SOC 3 report instead, which covers the same Trust Services Criteria at a high level without the detailed control testing.
How long does it take and what does it cost? A first Type I report typically takes three to six months end to end; a first Type II report takes six to fifteen months, mostly driven by the length of the observation period chosen. Audit fees range widely with scope and company size, and total implementation cost – policies, control work, internal effort – is usually larger than the audit fee itself.
Does a SOC 2 report expire? Not technically, but it’s considered outdated after about 12 months. Most organisations undergo a fresh Type II audit annually to keep a current report in hand for ongoing customer due diligence.
Related reading: What Is SOC 2? · SOC 2 Type 1 vs Type 2 · SOC 2 vs ISO 27001
How GCAI helps: GCAI’s readiness assessment can answer most of the questions above for your specific business in a single working session – including which Trust Services Criteria you actually need.