All frameworks
    AttestationAICPA (American Institute of Certified Public Accountants)

    SOC 2

    SOC 2: System and Organization Controls 2

    SOC 2 is an AICPA attestation report that shows how a company protects customer data. A licensed CPA firm tests your controls and issues an independent opinion.

    Last verified Jul 25, 2026

    Q&A

    What is SOC 2?

    SOC 2 is an AICPA attestation report that shows how a company protects customer data. A licensed CPA firm tests your controls and issues an independent opinion.

    Who needs SOC 2?

    B2B software and cloud companies that store or process customer data, especially those selling to US enterprises. SOC 2 is the report mid-market and enterprise procurement teams request most often during vendor security reviews, so it is usually the first framework a growing SaaS company is asked to produce.

    How long does SOC 2 take?

    Readiness and remediation usually take two to six months. A Type I is issued at a point in time; a Type II requires an observation window, commonly three months for a first audit and six to twelve months thereafter, before the report is issued.

    How much does a SOC 2 audit cost?

    Auditor fees: SOC 2 Type I typically $10,000 to $20,000; Type II $20,000 to $50,000 in year one, dropping to roughly 60 to 80% of that in later years. All-in first-year cost (auditor fee plus readiness tooling plus internal time) commonly $50,000 to $80,000 for an early-stage SaaS, with $20,000 to $60,000 all-in for very small scopes. See the full breakdown in our SOC 2 audit cost guide. For a deeper look at pricing drivers and typical ranges, see our full SOC 2 audit cost breakdown.

    What does a SOC 2 audit cover?

    An independent CPA firm tests the design (Type I) and operating effectiveness (Type II) of your controls against the selected Trust Services Criteria and issues an opinion. The deliverable is a formal report you can share under NDA.

    What it is

    SOC 2 is not a certification you pass or fail. It is an attestation. An independent, licensed CPA firm examines the controls your organization has in place to protect customer data and issues a report expressing an opinion on how well those controls are designed and, for a Type II, how well they operated over a period of time.

    The report is built around the AICPA's Trust Services Criteria. Security (the Common Criteria) is mandatory in every SOC 2. The other four criteria, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and included only when relevant to your service. You scope the report with your auditor based on what your customers actually care about.

    There are two report types. A SOC 2 Type I assesses whether controls are suitably designed at a single point in time. A SOC 2 Type II assesses whether they also operated effectively across an observation window, typically three to twelve months. Enterprise buyers almost always want a Type II.

    Who needs it

    B2B software and cloud companies that store or process customer data, especially those selling to US enterprises. SOC 2 is the report mid-market and enterprise procurement teams request most often during vendor security reviews, so it is usually the first framework a growing SaaS company is asked to produce.

    What's audited

    An independent CPA firm tests the design (Type I) and operating effectiveness (Type II) of your controls against the selected Trust Services Criteria and issues an opinion. The deliverable is a formal report you can share under NDA.

    Typical timeline

    Readiness and remediation usually take two to six months. A Type I is issued at a point in time; a Type II requires an observation window, commonly three months for a first audit and six to twelve months thereafter, before the report is issued.

    Typical cost

    Auditor fees: SOC 2 Type I typically $10,000 to $20,000; Type II $20,000 to $50,000 in year one, dropping to roughly 60 to 80% of that in later years. All-in first-year cost (auditor fee plus readiness tooling plus internal time) commonly $50,000 to $80,000 for an early-stage SaaS, with $20,000 to $60,000 all-in for very small scopes. See the full breakdown in our SOC 2 audit cost guide.

    What to verify on an auditor

    SOC 2 opinions can only be issued by a licensed CPA firm. Confirm an active CPA license, AICPA peer review, and independence from the tooling used to prepare you. An auditor that also sells you the compliance software it is auditing has a conflict.

    Service pathways

    Not every service under this framework is fully available today. Hover a pathway for context.

    • Readiness assessment
      Available
    • SOC 2 Type I attestation
      Available
    • SOC 2 Type II attestation
      Available

    Find SOC 2 auditors by region

    Browse independent SOC 2 auditors serving each region.