Service Organization Control 2 attestation, defined by the American Institute of CPAs (AICPA), covering the security, availability, processing integrity, confidentiality, and privacy trust service criteria.
Last updated — August 22, 2026
Primarily SaaS providers and service organizations whose clients — particularly North American or international enterprises — require formal assurance over the security and reliability of their operations as part of procurement or due diligence.
SOC 2 is based on the AICPA's Trust Services Criteria: security (mandatory), and depending on the chosen scope, availability, processing integrity, confidentiality, and privacy. The organization must demonstrate, with supporting evidence, that internal controls covering these criteria are in place either over a defined period (Type II report) or at a specific point in time (Type I report), both produced by an independent CPA audit firm.
Deadlines
SOC 2 is not a legal obligation and has no regulatory deadline; the timeline is driven by client commercial requirements (tenders, contracts), with a Type II report typically renewed annually to remain valid evidence.
Sanctions
There is no legal sanction tied to the absence of SOC 2. The risk is commercial: inability to respond to certain tenders, loss of trust from prospects or clients requiring the attestation, or contractual clauses conditioning the business relationship on producing it.
Selecting the relevant Trust Services Criteria scope (security mandatory, other criteria based on client expectations)
Readiness assessment
Implementation and documentation of internal controls
Control observation period (for a Type II report)
Audit by an independent CPA firm and issuance of the report
| Framework | Covered |
|---|---|
| iso-27001 | ✓ |
Get the checklist by email.
No, it is a voluntary process undertaken in response to client commercial requirements, mainly within the North American and international SaaS and digital services ecosystem.
Type I assesses the design of controls at a point in time, while Type II assesses their operating effectiveness over an observation period (typically 3 to 12 months), making it the more commercially sought-after report.
No, they are complementary. ISO 27001 is a management system certification, SOC 2 is an audit attestation against trust criteria; an organization with an existing ISO 27001 ISMS has a reusable control base for SOC 2.
Counting preparation, the control observation period, and the audit, a first Type II report typically takes several months, with the exact duration depending on initial maturity and the chosen observation period.