How to read aa GRC Score
Compliance

What Is SOC 2? A Straightforward Guide to SOC 2 Compliance

August 24, 2026

What Is SOC 2?

SOC 2 is a framework built by the American Institute of Certified Public Accountants (AICPA) to check how a company looks after customer data. If you're asking "what is SOC 2" for the first time, think of it as a formal check-up: an independent auditor looks at your security practices and writes a report on what they found. That report is what your customers, prospects, and partners will ask to see before they trust you with their data.

SOC 2 Isn't a Certification: Here's What It Actually Is

A lot of people call it a "SOC 2 certificate," but that's not quite right. SOC 2 compliance results in a report, not a certificate or a badge you hang on your website (though many companies do add a small trust seal once they've passed). The report is produced by a licensed CPA firm and lays out exactly which controls were tested, how they were tested, and whether they held up. This distinction matters because customers reviewing your soc 2 reporting will expect to read an actual report, not a logo.

The Five Trust Services Criteria, Explained Simply

Every SOC 2 audit is measured against five criteria, though only one is compulsory:

  • Security – stopping unauthorised access; the one criterion every audit must include
  • Availability – keeping systems up and running as promised
  • Processing integrity – making sure data is processed accurately, completely, and on time
  • Confidentiality – restricting sensitive data to the people who actually need it
  • Privacy – handling personal information the way your privacy notice says you will

Most companies start with Security alone, then add the others as their customer base and contracts demand more.

SOC 2 Type I vs Type II

This trips a lot of people up. A Type I report checks whether your controls are designed properly on one specific day. A Type II report checks whether those same controls actually worked, consistently, over a period of three to twelve months. Type I is quicker and cheaper to get, so it's useful if you're under contract pressure. But most customers now expect Type II, since it proves your controls hold up over time rather than just on paper.

Who Needs SOC 2?

SOC 2 applies to service organisations such as, cloud platforms, SaaS providers, data processors, and any company that stores or handles customer data on someone else's behalf. It's not a legal requirement anywhere. Nobody will fine you for skipping it. But if you're selling to enterprise customers, especially in the US, you'll hit a wall in procurement without one. UK and European buyers increasingly ask for it too, alongside or instead of ISO 27001.

How a SOC 2 Audit Actually Works

  1. You pick your scope, Security only, or Security plus other criteria
  2. You build and document the controls needed to meet those criteria
  3. You run a readiness assessment to catch gaps before the real audit
  4. An independent CPA firm tests your controls and gathers evidence
  5. You receive a report rated Unqualified (passed), Qualified (minor issues), Adverse (failed), or Disclaimer (not enough evidence to judge)

How Long It Takes and What It Costs

A Type I audit can be done in a matter of weeks once your controls are in place. A Type II audit needs a minimum observation window, usually three to twelve months, before the auditor can test anything. Costs vary widely depending on company size and scope, but budgeting for both the audit itself and the internal time spent gathering evidence is sensible, the second cost is usually the one people underestimate.

SOC 2 vs SOC 1 vs SOC 3

SOC 1 looks at controls relevant to financial reporting, which is for auditors and not customers. SOC 2 covers security, availability, processing integrity, confidentiality, and privacy, which is for customers and partners who want assurance over your data handling. SOC 3 is essentially a public-facing summary of a SOC 2 report, stripped of sensitive detail, so you can share it freely on your website rather than under NDA.

SOC 2 for UK and EU Businesses

SOC 2 is an American standard, but that doesn't stop UK and EU companies using it. Many do, particularly if they sell into the US market. The closest international equivalent auditors reference is ISAE 3000, which follows a similar structure. If your customers are mostly in the UK or EU, ISO 27001 is often asked for alongside SOC 2. We’ve seperately written about how SOC 2 and ISO 27001 fit together in our GRC Maturity Framework guide. Running both isn't as painful as it sounds, since the Security criterion in SOC 2 overlaps heavily with ISO 27001's controls, so evidence can often be reused.

How to Read a SOC 2 Report as a Buyer

If a vendor sends you their SOC 2 report, don't just check the cover page. Look at the auditor's opinion (you want Unqualified), check which Trust Services Criteria were actually in scope, and read the exceptions section; this lists any control that didn't work as intended during testing. A report with a couple of minor exceptions and a clear remediation plan is often more trustworthy than one claiming zero issues at all.

Common SOC 2 Myths, Busted

"SOC 2 means you're hack-proof"

No, it means your controls were tested and held up during the audit window.

"Any auditor can issue one"

No, only a licensed CPA firm can.

"You need all five criteria"

No, Security is the only mandatory one.

"It's a one-off project"

No, soc2 compliance means ongoing monitoring, not a single sprint before the audit.

How GRCI Can Help

Working out where you actually stand before you call an auditor saves time and money. GRCI runs a free GRC assessment that benchmarks your organisation against SOC 2's Trust Services Criteria, ISO 27001, and other core frameworks. It takes under 20 minutes and gives you a GRC Score, which shows you exactly where the gaps are, and hands you a plan to fill them, all before you spend a penny on a formal audit. If SOC 2 compliance is on your roadmap, start with your baseline at grci.net.

FAQs

What is a SOC 2 in the UK?

In the UK, SOC 2 works the same way as anywhere else, it's a US-originated AICPA framework, not a UK-specific one. UK companies pursue it voluntarily, usually because a US customer or a global enterprise buyer asks for it during procurement.

Is SOC 2 the same as ISO 27001?

No. They're separate standards with overlapping goals. SOC 2 is a US audit report built around five Trust Services Criteria; ISO 27001 is an international certification built around an information security management system. Many organisations pursue both, reusing evidence between them.

Is SOC 2 mandatory?

No. There's no law requiring it. It becomes a practical necessity when your customers, particularly enterprise or US-based ones, won't sign a contract without seeing a report.

Who does SOC 2 apply to?

Any service organisation that stores, processes, or transmits customer data, this covers SaaS platforms, cloud hosting providers, data processors, and managed service providers of most kinds.

GRC Assessment & Benchmarking

Evaluate your governance, risk, and compliance performance. Receive your GRC Score. Join organisations & professionals building verifiable, standards-based trust.