Guide · privacy-security

What Is SOC 2 Compliance? A Buyer's and Builder's Guide

SOC 2 is an audit of whether a company follows its own stated security controls. This guide covers what the report actually proves, the difference between Type I and Type II, and how to read one.

By stackzen-desk · Editorial reviews deskLast updated August 13, 2026

What it is

SOC 2 is an audit, performed by an independent accounting firm, of whether a company actually follows the security controls it says it follows. It is organised around five trust services criteria — security, availability, processing integrity, confidentiality, and privacy — of which security is mandatory and the rest are included at the company's choice. The output is a report, not a certificate, and that distinction matters more than most people realise.

What it does and does not prove

A SOC 2 report proves that a company defined controls and that an auditor tested them. It does not prove the controls are good, that the product is secure, or that a breach cannot happen. A company can pass with a modest control set competently followed, and a company with strong engineering can lack a report entirely because nobody has paid for the audit. Treating it as a security score rather than as evidence of process discipline is the most common misreading on both sides of a deal.

Type I versus Type II

Type I says the controls were designed appropriately and existed on one date. Type II says they operated effectively over a period, usually three to twelve months. The gap between them is large: Type I is a photograph, Type II is a video. Enterprise buyers generally want Type II, and a vendor offering only Type I is usually early in the process rather than done with it. When someone says "we're SOC 2", asking which type and what observation window is a reasonable and revealing question.

How to actually read a report

Go to the exceptions. Every report has a section listing controls that were not fully met during the period, and that is the only part carrying real information — the rest is largely boilerplate. Then check the scope: which systems and which trust criteria were covered, because a report scoped to one product does not cover the one you are buying. Then check the date: a report from eighteen months ago describes a company that may no longer exist in the same form. A vendor who will not share the full report under NDA and offers only a badge has told you something.

What it costs to get

For a small company, expect meaningful money and more meaningful time. There is the auditor's fee, usually a compliance-automation platform to collect evidence continuously, and — the part that is always underestimated — internal effort: writing policies, implementing access reviews, centralising logs, running background checks, documenting onboarding and offboarding. The first Type II also requires waiting out the observation window, so the timeline is measured in quarters, not weeks. Starting it the day a large deal demands it means missing that deal.

When it is worth pursuing

The honest trigger is commercial: when deals are stalling in security review, or when your buyers are companies whose procurement requires it. Getting it before that is expensive insurance against a problem you may not have. What is worth doing early, regardless, is the underlying hygiene — least-privilege access, audit logging, offboarding that actually removes access, encrypted backups you have tested restoring. That work is the substance the audit checks for, and it has value whether or not anyone audits it.

A note on adjacent frameworks

ISO/IEC 27001 covers similar ground for international buyers and certifies a management system rather than reporting on controls; European customers often prefer it. SOC 2 is not a privacy law — GDPR obligations exist independently, and a SOC 2 report says nothing about whether you have a lawful basis for the data you hold.

More guides