
SOC 2 is a framework built by the American Institute of Certified Public Accountants (AICPA) to check how a company looks after customer data. If you're asking "what is SOC 2" for the first time, think of it as a formal check-up: an independent auditor looks at your security practices and writes a report on what they found. That report is what your customers, prospects, and partners will ask to see before they trust you with their data.
A lot of people call it a "SOC 2 certificate," but that's not quite right. SOC 2 compliance results in a report, not a certificate or a badge you hang on your website (though many companies do add a small trust seal once they've passed). The report is produced by a licensed CPA firm and lays out exactly which controls were tested, how they were tested, and whether they held up. This distinction matters because customers reviewing your soc 2 reporting will expect to read an actual report, not a logo.
Every SOC 2 audit is measured against five criteria, though only one is compulsory:
Most companies start with Security alone, then add the others as their customer base and contracts demand more.
This trips a lot of people up. A Type I report checks whether your controls are designed properly on one specific day. A Type II report checks whether those same controls actually worked, consistently, over a period of three to twelve months. Type I is quicker and cheaper to get, so it's useful if you're under contract pressure. But most customers now expect Type II, since it proves your controls hold up over time rather than just on paper.
SOC 2 applies to service organisations such as, cloud platforms, SaaS providers, data processors, and any company that stores or handles customer data on someone else's behalf. It's not a legal requirement anywhere. Nobody will fine you for skipping it. But if you're selling to enterprise customers, especially in the US, you'll hit a wall in procurement without one. UK and European buyers increasingly ask for it too, alongside or instead of ISO 27001.
A Type I audit can be done in a matter of weeks once your controls are in place. A Type II audit needs a minimum observation window, usually three to twelve months, before the auditor can test anything. Costs vary widely depending on company size and scope, but budgeting for both the audit itself and the internal time spent gathering evidence is sensible, the second cost is usually the one people underestimate.
SOC 1 looks at controls relevant to financial reporting, which is for auditors and not customers. SOC 2 covers security, availability, processing integrity, confidentiality, and privacy, which is for customers and partners who want assurance over your data handling. SOC 3 is essentially a public-facing summary of a SOC 2 report, stripped of sensitive detail, so you can share it freely on your website rather than under NDA.
SOC 2 is an American standard, but that doesn't stop UK and EU companies using it. Many do, particularly if they sell into the US market. The closest international equivalent auditors reference is ISAE 3000, which follows a similar structure. If your customers are mostly in the UK or EU, ISO 27001 is often asked for alongside SOC 2. We’ve seperately written about how SOC 2 and ISO 27001 fit together in our GRC Maturity Framework guide. Running both isn't as painful as it sounds, since the Security criterion in SOC 2 overlaps heavily with ISO 27001's controls, so evidence can often be reused.
If a vendor sends you their SOC 2 report, don't just check the cover page. Look at the auditor's opinion (you want Unqualified), check which Trust Services Criteria were actually in scope, and read the exceptions section; this lists any control that didn't work as intended during testing. A report with a couple of minor exceptions and a clear remediation plan is often more trustworthy than one claiming zero issues at all.
"SOC 2 means you're hack-proof"
No, it means your controls were tested and held up during the audit window.
"Any auditor can issue one"
No, only a licensed CPA firm can.
"You need all five criteria"
No, Security is the only mandatory one.
"It's a one-off project"
No, soc2 compliance means ongoing monitoring, not a single sprint before the audit.
Working out where you actually stand before you call an auditor saves time and money. GRCI runs a free GRC assessment that benchmarks your organisation against SOC 2's Trust Services Criteria, ISO 27001, and other core frameworks. It takes under 20 minutes and gives you a GRC Score, which shows you exactly where the gaps are, and hands you a plan to fill them, all before you spend a penny on a formal audit. If SOC 2 compliance is on your roadmap, start with your baseline at grci.net.
In the UK, SOC 2 works the same way as anywhere else, it's a US-originated AICPA framework, not a UK-specific one. UK companies pursue it voluntarily, usually because a US customer or a global enterprise buyer asks for it during procurement.
No. They're separate standards with overlapping goals. SOC 2 is a US audit report built around five Trust Services Criteria; ISO 27001 is an international certification built around an information security management system. Many organisations pursue both, reusing evidence between them.
No. There's no law requiring it. It becomes a practical necessity when your customers, particularly enterprise or US-based ones, won't sign a contract without seeing a report.
Any service organisation that stores, processes, or transmits customer data, this covers SaaS platforms, cloud hosting providers, data processors, and managed service providers of most kinds.
© 2025 GRC Index. All rights reserved.