SOC 2 — Trust Services Criteria

The attestation report North American enterprise buyers ask for by name, issued by an independent CPA firm against the Trust Services Criteria.

American Institute of Certified Public Accountants (AICPA). Reports are issued by independent CPA firms.

What it is

SOC 2 is an attestation report on a service organisation's controls, developed by the American Institute of Certified Public Accountants. It is the report North American enterprise buyers ask for by name, and increasingly one that Australian companies selling into the United States are expected to hold.

It is assessed against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security is always in scope; the others are included only where relevant to what you promise customers. Choosing more criteria than you need is a straightforward way to make the engagement more expensive than it had to be.

Two report types matter:

  • Type I tests whether controls are suitably designed at a point in time.
  • Type II tests whether they operated effectively across a period — typically three to twelve months. This is what most enterprise buyers actually want.

An important distinction from ISO certification. SOC 2 is not a certification and there is no certificate. It is an attestation report issued by an independent CPA firm, containing the auditor's opinion. No consultancy can issue one, and any that claims to is misrepresenting the scheme.

Who it's for

SaaS and technology companies selling into North America

The dominant case. US enterprise procurement asks for SOC 2 the way Australian procurement asks for ISO 27001, and the absence of one stalls deals at the security review stage.

Service organisations holding customer data

Anywhere a customer's own compliance depends on the controls you operate on their behalf.

Companies selling into both markets

Where SOC 2 and ISO 27001 are both asked for. The underlying controls overlap heavily, so building them together costs far less than running two separate programmes.

Who should think twice

An organisation with no North American buyers asking for it. SOC 2 is a recurring cost with an annual cycle, and ISO 27001 is usually the better first investment for a business selling into Australia, Europe or government.

Why implement it

  • It unblocks North American enterprise sales. For most organisations that pursue it, this is the entire business case, and it is usually a specific stalled deal.
  • Type II carries real weight. Because it tests operating effectiveness over a period rather than design at a point, buyers treat it as meaningful evidence rather than a formality.
  • It is flexible on scope. Criteria are selected against what you actually promise customers, so the report reflects your service rather than a generic template.
  • It pairs efficiently with ISO 27001. Access control, change management, vendor management, monitoring and incident response serve both, so the second is far cheaper than the first.
  • The evidence discipline is the real benefit. A Type II observation window forces controls to actually run and generate records, which is a genuine operational improvement rather than a paperwork exercise.

How implementation works

1. Select criteria and scope

Security is required; the other four are included only where relevant to what you promise customers. Adding criteria you do not need is a common and avoidable cost.

2. Gap assessment

Against the applicable criteria, establishing what exists and what has to be built.

3. Build the control environment

Policies, access control, change management, vendor management, incident response, monitoring — and, critically, the routines that generate evidence as a by-product of normal operation.

4. Operate through the observation window

For Type II, this is the substance of the engagement. The auditor samples evidence across the period, so controls must be running and producing records throughout. There is no way to compress this.

5. Auditor fieldwork

The CPA firm tests controls and evidence. Soveriq supports the process; the opinion is the auditor's.

6. Report issued, then repeat

Reports cover a stated period, so buyers expect a current one. Plan for a recurring annual cycle rather than a one-off project.

How Soveriq helps

Soveriq builds the control environment and the evidence routines inside the systems you already run, so the observation window produces records naturally rather than requiring a reconstruction exercise at audit time.

Where ISO 27001 is also needed, we scope both together. The control overlap is substantial and the marginal cost of the second is far lower than doing them separately — which matters for any Australian company selling into both markets.

Being direct about the boundary. Soveriq is not a CPA firm and cannot issue a SOC 2 report. We prepare you and support the audit; the attestation is issued independently. That separation is the point of the report, and any provider blurring it is devaluing the thing you are buying.

On internal review. Where Soveriq has built your control environment, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What the engagement looks like

  • Module 01 — Gap analysis against the applicable Trust Services Criteria, including scope and criteria selection.
  • Module 02 — Build. Control environment, policy set and the evidence-generating routines the observation window depends on.
  • Module 03 — Internal review ahead of the audit, subject to the impartiality position above.
  • Module 04 — Audit support through the CPA firm's fieldwork.
  • Module 05 — Continuous compliance across the observation window and into the next report period.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day. CPA firm fees are separate and paid directly to that firm.

Common questions

Can Soveriq issue our SOC 2 report?

No. A SOC 2 report can only be issued by an independent CPA firm. We prepare the control environment and evidence; the attestation is theirs. Any consultancy claiming to issue SOC 2 reports is describing something it cannot do.

Type I or Type II?

Type I tests design at a point in time and is faster. Type II tests operating effectiveness over a window and is what most enterprise buyers actually want. Type I is a reasonable staging post if a deal needs something immediately, but budget for Type II.

SOC 2 or ISO 27001?

It depends on the buyer. North American enterprise buyers usually ask for SOC 2. Australian, European and government buyers usually ask for ISO 27001. Organisations selling into both markets often need both, and because the underlying controls overlap heavily, doing them together is far cheaper than sequentially.

How long is a SOC 2 report valid?

It covers a stated period rather than carrying an expiry. In practice buyers expect a report covering a recent period, which usually means an annual cycle. A report more than twelve months old starts drawing questions.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope