
SOC 2 is one of the most requested security standards in enterprise procurement today. If a potential customer or investor has ever asked for your SOC 2 report, this guide explains exactly what that means.
SOC 2 stands for System and Organisation Controls 2. It is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA). It verifies that a service organisation's controls meet defined standards for data protection, system availability, and operational reliability.
This guide covers what SOC 2 is, the five Trust Services Criteria it is built on, the difference between Type 1 and Type 2, and how SOC 2 applies to UK and EU organisations.
SOC 2 is a voluntary auditing standard that evaluates how a service organisation manages the security and privacy of the data it holds on behalf of its customers. It applies to any organisation that stores, processes, or transmits customer data using cloud-based or hosted systems.
The AICPA publishes the Trust Services Criteria that govern SOC 2 audits. An independent Certified Public Accountant (CPA) firm conducts the audit and issues a SOC 2 report. That report is the deliverable your customers and business partners will request.
SOC 2 is an attestation, not a formal certification. There is no governing body that issues a certificate. The phrase 'SOC 2 certified' is commonly used in the market, but the correct term is 'SOC 2 attested' or 'SOC 2 compliant'.
SOC 2 audits are structured around five Trust Services Criteria (TSC). Security is mandatory for every SOC 2 engagement. The other four criteria are optional and are included based on what is relevant to your organisation's services.
Security is the Common Criteria and forms the foundation of every SOC 2 audit. It covers logical and physical access controls, monitoring, incident response, and risk management. The AICPA's Common Criteria are aligned with the COSO Internal Control framework.
Availability covers whether your systems and services are accessible as agreed in your service commitments. It includes monitoring system performance, disaster recovery, and business continuity planning. This criterion is relevant to organisations providing infrastructure, SaaS platforms, or uptime-dependent services.
Processing Integrity evaluates whether your system processes data completely, accurately, on time, and only as authorised. It applies most directly to organisations handling financial transactions, order processing, or data transformation workflows.
Confidentiality assesses how your organisation protects information designated as confidential. This includes data classification, encryption, access controls, and secure disposal. It is particularly relevant for organisations handling commercially sensitive data or proprietary client information.
Privacy evaluates your handling of personal information in line with your stated privacy notice and the AICPA's Privacy Management Framework. It covers collection, use, retention, disclosure, and disposal of personal data. For UK and EU organisations, this criterion complements GDPR compliance obligations.
There are two types of SOC 2 reports. Understanding the difference matters because customers and investors will ask for one or both.
Type 1: Evaluates whether controls are suitably designed at a single point in time.
Type 2: Evaluates whether controls operated effectively over a period of 6 to 12 months.
Use Type 1 for: Initial market entry, demonstrating readiness, early-stage procurement requirements.
Use Type 2 for: Enterprise procurement, regulated industries, investor due diligence.
Both types: Conducted by an independent CPA firm. Security criterion is mandatory in both.
Most enterprise buyers and regulated financial institutions will ultimately require a SOC 2 Type 2 report. A Type 1 report is a useful intermediate step that demonstrates commitment and control design while the Type 2 observation period runs.
The observation period for Type 2 is typically six to twelve months. This means planning your SOC 2 programme early is important, particularly if a customer deadline is driving the requirement.
SOC 2 originated in the United States but has become a global standard. UK and EU service organisations are increasingly asked to provide SOC 2 reports as part of enterprise procurement and vendor risk management processes.
The following types of organisations commonly need SOC 2:
In the UK, SOC 2 has grown in relevance alongside FCA conduct requirements, DORA operational resilience obligations, and NIS2 supply chain security requirements. Enterprise buyers in financial services, insurance, and public sector often include SOC 2 in procurement questionnaires alongside ISO 27001.
For UK organisations, SOC 2 also aligns well with Provision 29 of the UK Corporate Governance Code 2024, which requires boards to declare the effectiveness of material controls from financial years beginning 1 January 2026.
SOC 2 is not a standalone checklist. It is one component of a broader governance, risk, and compliance (GRC) programme. Organisations that approach SOC 2 in isolation often spend significantly more time and money than those that build it into an integrated GRC framework.
The controls required for SOC 2's Security criterion overlap substantially with ISO 27001. Organisations pursuing both standards can often share evidence, policies, and controls across both audits. Similarly, SOC 2's Privacy criterion builds on GDPR compliance work already completed.
The GRC Index assessment benchmarks your organisation across six GRC domains including Information Security, which covers SOC 2 Trust Services Criteria readiness. Completing a benchmark assessment gives you a baseline score and a prioritised improvement roadmap before you engage an auditor.
Not sure where your organisation stands against SOC 2 requirements?
The GRC Index assessment is free, independent, and benchmarked against AICPA Trust Services Criteria.
You receive a GRC Score, a public profile in the Index, and a prioritised improvement plan.
Start your assessment at grci.net | It takes under 20 minutes to complete.
SOC 2 is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how a service organisation manages customer data across five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Organisations that pass a SOC 2 audit receive a report they can share with customers and business partners.
SOC 2 is an attestation, not a certification. An independent CPA firm audits your controls and issues a SOC 2 report. No governing body issues a certificate. The term 'SOC 2 certified' is widely used informally, but the technically correct terms are 'SOC 2 attested' or 'SOC 2 compliant'.
SOC 2 Type 1 evaluates whether your security controls are suitably designed at a single point in time. SOC 2 Type 2 evaluates whether those controls operated effectively over a period of six to twelve months. Type 2 carries more evidential weight with enterprise customers and investors. Most organisations start with Type 1 and progress to Type 2.
Any UK or EU service organisation that stores, processes, or transmits customer data may be asked to provide a SOC 2 report. It is most common in SaaS, cloud services, financial technology, managed services, and healthcare technology. Enterprise buyers and regulated financial institutions increasingly require SOC 2 as a vendor qualification criterion.
A SOC 2 Type 1 audit typically takes three to six months from readiness assessment to report. A Type 2 audit requires a six to twelve month observation period on top of that. Planning your SOC 2 programme nine to eighteen months before a customer deadline is advisable.
© 2025 GRC Index. All rights reserved.