Back to Blog

What is SOC 2? A Complete 2026 Guide for Founders and Ops Leads

Plain-English explainer of SOC 2 — what it actually is, why enterprise buyers ask for it, how the Trust Services Criteria work, Type I vs Type II, cost, timeline, and how to decide if your company needs it. No jargon.

Quick Answer

Plain-English explainer of SOC 2 — what it actually is, why enterprise buyers ask for it, how the Trust Services Criteria work, Type I vs Type II, cost, timeline, and how to decide if your company needs it. No jargon.

A founder gets an email on a Tuesday afternoon from a prospect she’s been chasing for four months. The buyer is ready to move to procurement. Attached to the email is a 40-question security review that opens with: “Please attach your most recent SOC 2 Type II report.” The founder types “what is SOC 2” into a search bar. Every result assumes she already knows.

This is that missing article — the actual plain-English explanation of what SOC 2 is, what it isn’t, when a company needs it, what it costs, and how long it takes. No jargon, no fear-mongering. If you’re a founder or ops lead who just got a SOC 2 request and needs to understand what you’re actually being asked for, start here.

The one-sentence answer

SOC 2 is an audit report a licensed CPA firm issues describing your organization’s security controls — enterprise customers ask for it as evidence that your security program actually exists and works. It is not a certification, not a law, and not the same thing as ISO 27001.

What SOC 2 actually is

SOC 2 stands for Service Organization Control 2. It’s a professional auditing framework published by the AICPA — the American Institute of Certified Public Accountants — the same body that governs how CPAs audit financial statements. A licensed CPA firm evaluates your organization against a specific set of criteria (the Trust Services Criteria) and issues an attestation report describing what they observed.

Three things it is not:

  • Not a certification. There is no SOC 2 certificate. The output is a report. You cannot “pass” SOC 2 the way you pass a driving test. Colloquially people say “we got SOC 2 certified” but the AICPA does not use that term. The correct phrasing is “we completed a SOC 2 Type II attestation.”
  • Not a law. SOC 2 is market-driven, not legally required. HIPAA, PCI DSS, GDPR — those are legal or contractual obligations. SOC 2 is not. You do SOC 2 because your customers ask for it, not because a regulator will fine you.
  • Not the same as ISO 27001. ISO 27001 is an international standard with an actual certificate. SOC 2 is a US-originated attestation framework. Enterprise buyers often accept either. They are functionally similar but structurally different.

What SOC 2 actually is: a signal to enterprise buyers that a third-party CPA firm has looked at your security controls, observed them operating over time, and written a report describing them. The report is meant to be read by the buyer’s security or procurement team. It gives them evidence that your security program is more than a vendor’s marketing claim.

$12K–$30K
Typical SOC 2 Type II audit cost for a small/mid-market SaaS at 20-100 employees (Drata 2026 SOC 2 cost guide)
6–12 months
Realistic timeline from readiness kickoff to signed Type II report for a first-time SOC 2 at SaaS scale
3 months min
Minimum observation window for a first-time Type II per AICPA guidance; 6-12 months is stronger for enterprise buyer confidence

The Trust Services Criteria (TSC) — what SOC 2 actually evaluates

Every SOC 2 audit evaluates your organization against the Trust Services Criteria, published by the AICPA. There are five categories. Security is mandatory for every SOC 2 report. The other four are optional and only in scope if the customer requests them or the vendor chooses to include them.

TSC Category
What it evaluates
How common in first SOC 2
Security (Common Criteria)
Access controls, change management, vulnerability management, monitoring, incident response, risk assessment, governance. Nine sub-criteria: CC1 (control environment) through CC9 (risk mitigation).
Mandatory. Every SOC 2 report includes Security.
Availability
System uptime, disaster recovery, backup and restore, capacity planning. Whether your service is accessible when contractually promised.
Second most common. Include if customer contracts have uptime SLAs or if you serve business-critical workloads.
Confidentiality
How non-personal confidential data (customer business data, source code, trade secrets) is protected in transit, at rest, and in disposal.
Third most common. Include if you handle proprietary business data your customers consider trade secrets.
Processing Integrity
Whether your system processes data accurately, completely, timely, and with authorization. Whether inputs, processing, and outputs produce the right result.
Uncommon in first reports. Include if you're a payments, transaction-processing, or data-transformation platform.
Privacy
How personally identifiable information (PII) is collected, used, retained, disclosed, and disposed of, aligned with your privacy notice.
Rare in first reports. Most companies rely on GDPR/CCPA compliance separately and don't include Privacy in SOC 2 scope.

The Security category alone contains 33 controls spread across nine sub-criteria (CC1-CC9). Each control has evidence expectations that the auditor tests during fieldwork. Most first SOC 2 reports scope Security only; adding another category typically increases audit cost by 15-25% and readiness work by roughly the same.

Type I vs Type II — the difference that matters to buyers

There are two report types. Enterprise customers almost always want Type II. Understanding why is the difference between a report that closes deals and a report that gets pushed back on.

Type I
Type II
What it evaluates
Controls exist and are designed appropriately as of a single point in time (a specific date).
Controls exist AND operated effectively over a period of time (3-12 month observation window).
How the auditor tests
Reviews policies, interviews staff, examines control configurations on the audit date. No sampling of operating history.
Reviews policies + samples evidence throughout the observation window. Tests whether the control fired consistently across the entire period.
Timeline to complete
60-90 days end-to-end for a first-time engagement.
6-12 months end-to-end. Readiness (60-90 days) + observation window (3-12 months) + fieldwork (2-4 weeks) + report (2-3 weeks).
Typical cost
$8,000-$18,000 for the audit itself.
$12,000-$30,000 for the audit itself (Drata 2026 cost guide); larger orgs run $30,000-$60,000+.
Buyer acceptance
Some enterprise buyers accept as an interim signal. Most want to see Type II within 6-12 months.
The standard expectation for enterprise procurement. Almost always required for deals above ~$50K ACV.
Common use case
Companies mid-sales-cycle who need something to hand the buyer before Type II is possible.
The report your enterprise pipeline actually needs. Renewed annually.
The one-sentence choice

If a buyer will accept it and your timeline allows, skip Type I and go directly to Type II. Type I is only worth it when you have a specific customer who needs proof faster than a Type II can deliver.

How the SOC 2 process actually works — start to finish

The end-to-end sequence for a first-time SOC 2 Type II at a 20-100 employee SaaS company:

Readiness assessment (weeks 1–3)

A vCISO, a compliance automation platform, or an internal security lead evaluates your current controls against the Security TSC. Output: a gap list of what's missing, what needs documentation, and what needs to be built. Sometimes this is called a 'readiness engagement' or 'gap assessment.' For a 30-person SaaS with reasonable but undocumented security practices, expect 15-40 gaps. This is normal.

Policy library and control remediation (weeks 3–10)

Build the policy library (Information Security Policy, Access Control Policy, Change Management Policy, Incident Response Plan, Vendor Management Policy, Business Continuity Plan, Data Classification Policy, Acceptable Use Policy — 8-12 policies at minimum). Close the gaps identified in the readiness assessment. Wire up evidence-collection tooling (MFA enforcement, access review cadence, change-management ticketing, vulnerability scanning, log aggregation).

Observation window (months 3–15)

The clock starts on the day the auditor confirms your controls are ready. For a first-time Type II with a 3-month window, this is 90 days of evidence collection. For a 6-month window (stronger for buyer confidence), it's 180 days. The auditor will sample evidence from this window during fieldwork. The single most common founder mistake is starting the window before evidence collection is actually working — the auditor finds gaps and the report lists exceptions.

Fieldwork (2–4 weeks)

The auditor conducts interviews with staff (typically 4-8 hours across engineering, security, and operations), samples evidence from the observation window, tests controls, and documents findings. If evidence is well-organized, fieldwork is efficient. If evidence is scattered across Slack, Google Drive, and engineer laptops, fieldwork slows down and cost goes up.

Report drafting and delivery (2–3 weeks)

The auditor drafts the report, walks through findings with you, gives you the chance to respond to any exceptions, and issues the final signed report. Total elapsed time from readiness kickoff to signed Type II: 6-12 months for most first-time engagements.

Renewal (annual thereafter)

Type II is a rolling annual report. Year two typically covers a 12-month observation window from the end of year one's window (or a 3-month gap and a fresh 12-month window). Renewal costs typically drop 20-40% because readiness is already done. Focus shifts to keeping evidence collection running consistently and remediating anything the previous audit flagged.

What SOC 2 actually costs

Total year-one SOC 2 cost is the sum of four things: the audit fee, the readiness work, the platform (if any), and the internal team time. Numbers below reflect what a 20-100 employee SaaS company typically pays.

Cost line
Typical range
What drives it up or down
SOC 2 Type II audit fee
$12,000–$30,000 for small/mid-market SaaS; $30,000–$60,000+ for larger orgs (Drata 2026 SOC 2 cost guide)
Company size, TSC scope (Security only vs Security+Availability+Confidentiality), auditor tier (Big 4 vs boutique CPA firm), observation window length
Readiness / gap remediation
$8,000–$40,000 in vCISO or consulting time
Starting maturity of your security program. A company with existing MFA + documented policies pays less than a company starting from zero
Compliance automation platform (optional)
$8,000–$60,000/yr for Vanta, Drata, Sprinto, Secureframe, or Hyperproof (all quote-only)
Framework count, headcount tier, integration depth. Platform-augmented vCISO subscriptions like vCISO Lite bundle this at $299–$1,499/mo published
Internal team time
40–120 person-hours across engineering, ops, and leadership
How much you outsource to vCISO / platform. Doing SOC 2 entirely in-house doubles the internal time
Total year-one out-of-pocket
$20,000–$100,000+ typical
Small companies with automation and a fractional vCISO land at $20K-$40K. Larger orgs or those choosing a Big 4 auditor pay $60K-$150K+
Year-two renewal
$10,000–$30,000 typically 20-40% cheaper than year one
Readiness already done; focus is on maintaining evidence and remediating prior exceptions
The cost signal enterprise buyers actually read

Enterprise procurement teams know roughly what SOC 2 costs. If a vendor claims SOC 2 Type II but the report is from an obscure CPA firm nobody has heard of, or the observation window is 60 days instead of 90+, or the exceptions list is short and vague, buyers notice. A well-scoped Type II from a reputable auditor with a full 6-12 month observation window signals a real program. A rushed Type I from a cut-rate auditor with a 30-day “observation window” signals a company that treated SOC 2 as a checkbox. The buyer’s security team can tell the difference.

Do you actually need SOC 2?

SOC 2 is not required by law. It’s a market signal. The question is not “is SOC 2 required for a SaaS company” — it isn’t. The question is “does my current buyer pipeline require it.” Six honest signals:

  • An enterprise buyer explicitly asked for it in the last 90 days. This is the strongest signal. If a real prospect on your pipeline attached a security questionnaire and the first bullet is “SOC 2 Type II report,” you need SOC 2. Timeline pressure is real.
  • Your competitor already has it and you’re losing deals. If your win-rate against a specific competitor is dropping and the buyer feedback references “security posture” or “compliance,” the competitor’s SOC 2 is likely part of it. Match to compete.
  • You’re selling to companies with a formal security review function. Any buyer with a CISO, a security team, or a compliance officer will ask for SOC 2 (or ISO 27001) at some point. The larger the buyer, the earlier in the sales cycle they ask.
  • Your ACV threshold is above ~$50K. Enterprise procurement gates typically kick in for annual contract values above roughly $50,000. Deals larger than that increasingly require SOC 2 as a procurement floor.
  • You’re raising a Series B or later and investors care about enterprise pipeline. Institutional VCs at Series B+ often ask about enterprise-readiness. SOC 2 is a low-friction way to signal that the company is enterprise-ready.
  • You handle regulated data (PHI, PCI cardholder data, government data) that triggers other frameworks. SOC 2 is often the umbrella your customers accept as evidence of the broader security program. HIPAA-covered entities often accept SOC 2 as part of BAA due diligence.

If none of the six apply — you’re pre-revenue or SMB-only, no buyer has asked, no regulated data, no enterprise pipeline — SOC 2 is probably not the highest-ROI compliance investment right now. Revisit in 6-12 months as your customer profile matures.

The four questions to ask before you start

Which auditor?

Type II reports from Big 4 (Deloitte, PwC, EY, KPMG) carry more weight with the largest enterprises but cost 2-3x more and often take longer. Boutique CPA firms (A-LIGN, Prescient Assurance, Insight Assurance, KirkpatrickPrice) are the default for mid-market SaaS — comparable quality, lower cost, faster turnaround. Most vCISO firms and compliance automation platforms have preferred auditor partnerships that discount 10-25%.

Which TSC scope?

Security only for first report unless a specific customer contract requires more. Adding Availability, Confidentiality, or Processing Integrity increases audit fees by 15-25% each and readiness work by similar amounts. Do it later if you need it later.

Type I first or straight to Type II?

Straight to Type II if your customer timeline allows. Type I is a fallback when you need to hand the customer something in 90 days and Type II won't complete for another 6-9 months.

In-house or platform-augmented?

In-house works if you have a security lead who can drive 100+ hours of readiness work while running the security program. If you don't have that person, a compliance automation platform ($8K-$60K/yr quote-only) or a platform-augmented vCISO ($299-$1,499/mo published on vCISO Lite pricing page) handles the readiness cycle with less internal-team overhead.

Common founder mistakes at their first SOC 2

  • Starting the observation window before evidence is actually flowing. The clock starts when you say it does, but the auditor tests evidence from the entire window. Starting the window while your access review process is still “we’ll do it in a Google Doc every quarter” means the auditor will find gaps and the report will list them as exceptions. Wait until evidence collection is running consistently for at least 30 days before starting the observation window.
  • Assuming the platform “does” SOC 2 for you. Compliance automation platforms handle evidence collection and framework mapping. They do not run your security program, write your incident response plan, or make sure your access reviews actually happen. Someone at your company still owns the program. Confuse this and the audit exposes it.
  • Under-scoping the readiness work. A 30-person SaaS starting from zero typically has 15-40 gaps at first assessment. Founders who plan a 60-day timeline are almost always surprised at week 4 that the actual work is closer to 120 days. Plan for 60-90 days of dedicated readiness time.
  • Picking the cheapest auditor without checking references. Enterprise procurement teams know which CPA firms are respected in the space. A report from an unknown auditor gets scrutinized harder. Ask peer companies who they used. Ask your vCISO or platform for their preferred auditors and why.
  • Treating SOC 2 as a one-time project instead of a program. Type II is annual. Evidence collection needs to run continuously. Founders who treat SOC 2 as “get the report and move on” discover at renewal that the evidence trail has gaps and readiness work has to happen again. Build the process, not just the report.
  • Not budgeting for the vCISO or program-owner role. The audit fee is the visible cost. The invisible cost is the 100-200 hours of internal or fractional security-lead time to run the program during the observation window. Founders who don’t budget for this end up doing it themselves at the expense of building product.

Frequently asked questions

What is SOC 2?

SOC 2 is an audit framework published by the AICPA. A CPA firm evaluates your security controls against the Trust Services Criteria and issues a report. Enterprise buyers ask for it as evidence of a real security program. Not a certification, not a law — a market-driven proof point.

Is SOC 2 a certification?

No. SOC 2 is an attestation report issued by a CPA firm. There is no SOC 2 certificate. Colloquially people say “SOC 2 certified” but the AICPA doesn’t use that term.

SOC 2 Type I vs Type II?

Type I is point-in-time; Type II covers a 3-12 month observation window and tests operating effectiveness. Enterprise buyers almost always want Type II. Skip Type I unless a specific customer needs proof faster than Type II can deliver.

How much does SOC 2 cost?

Audit fee $12K-$30K at small/mid-market SaaS (Drata 2026 cost guide); larger orgs $30K-$60K+. Total year-one out-of-pocket typically $20K-$100K including readiness and platform. Year-two renewal 20-40% cheaper.

How long does SOC 2 take?

6-12 months for a first-time Type II. Readiness 60-90 days; observation window 3-12 months; fieldwork 2-4 weeks; report 2-3 weeks. Type I in 60-90 days if you need something faster.

Does my SaaS company need SOC 2?

Only if enterprise customers ask for it, or your pipeline is gated on it. Not required by law. Signals to say yes: a real prospect asked in the last 90 days, competitors have it and you’re losing deals, or your ACV is above ~$50K.

Do crypto companies need SOC 2?

Yes, in almost every institutional-facing case. SOC 2 is what banking partners, custodians (Coinbase Custody, Fireblocks, BitGo, Anchorage), exchange integrations, and stablecoin issuers ask for before onboarding a counterparty — it’s the baseline attestation that turns a crypto startup into an institution-ready one.

The scope emphasis is different from a general SaaS SOC 2. Crypto companies should treat Availability, Confidentiality, and Processing Integrity as first-tier Trust Service Criteria alongside Security — the audit substance covers hot-vs-cold-wallet segregation, key-ceremony controls, signature-quorum policies, and smart-contract audit reports as evidence artifacts a general SaaS audit doesn’t have.

Important boundary: SOC 2 does not substitute for the crypto-specific regimes — NYDFS BitLicense, FinCEN MSB registration, state money transmitter licenses, or SEC broker-dealer requirements are separate compliance regimes. SOC 2 controls can feed into those (and are often required alongside them), but SOC 2 doesn’t replace them.

Scoping guide by business model: custodial platforms typically need SOC 2 Type II plus SOC 1 Type II (for financial-reporting controls that vendors and auditors expect from anything holding customer funds). Non-custodial wallets and DeFi front-ends often stop at SOC 2 Type II when institutional counterparties are the target.

SOC 2 vs ISO 27001 — which first?

For US-market SaaS with US enterprise buyers, SOC 2 first. ISO 27001 is stronger for European and multinational buyers. If both are asked, SOC 2 Type II first, then ISO 27001.

Bottom line

SOC 2 is a CPA-issued attestation report evaluating your security controls against the Trust Services Criteria. It’s not a certification, not a law, and not the same as ISO 27001. Enterprise buyers ask for it because it’s a professional-standards-backed signal that your security program is real. A first Type II costs $20K-$100K year-one and takes 6-12 months. The right time to start is when a real enterprise buyer on your pipeline has asked, or when you’re targeting a $50K+ ACV market where procurement gates will require it. Not before.

If SOC 2 is on your calendar for the next 6-12 months, the specifics are covered in the sibling articles below — the compliance automation buyer’s guide, the pricing breakdown, and the vCISO scope that runs the program during the observation window.

See vCISO Lite’s SOC 2 readiness pricing

vCISO Lite publishes its rate card — $299 to $1,499 per month across four tiers — and every tier includes SOC 2 readiness scope with a vCISO consultant whose hours scale with the plan. If you’re running a first-time SOC 2 at 20-100 employees, this is the platform-augmented option that covers evidence collection, policy library, and program ownership in one subscription.

If you just got a SOC 2 request from a real customer and need to figure out what’s next, visit vcisolite.com to learn more and get started.

Sources

  • AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017, revised 2022): aicpa-cima.com
  • Drata, SOC 2 Cost Guide 2026 (Type II small/midsize $12K-$20K, mid-market $30K-$60K, readiness $5K-$25K): drata.com/learn/soc-2/cost
  • vCISO Lite published pricing ($299-$1,499/mo across four tiers): vcisolite.com/pricing
  • Pivot Point Security (CBIZ Pivot Point) vCISO pricing ($4,500-$12,500/mo covers 90% of clients, April 2025 update): pivotpointsecurity.com

Where this matters next

SOC 2 Compliance Automation Tools: 2026 Buyer's Guidethe compliance automation platforms buyers evaluate when running SOC 2 — Vanta, Drata, Sprinto, Secureframe, Hyperproof feature comparison and pricing shape.

vCISO Pricing in 2026: Three Honest Tiersthe pricing tiers for the vCISO who runs the SOC 2 program during the observation window — platform-augmented, traditional consultancy, and heavy multi-jurisdictional.

SOC 2 Real Pricing and Timeline 2026the deeper pricing and timeline analysis for founders in the middle of scoping a first Type II.

What Changed in SOC 2 for 2026the auditor-expectation shifts for 2026 that affect what fieldwork looks like and which evidence gets scrutinized most.

SOC 2 vs ISO 27001: Which First, Which Secondthe decision framework for whether SOC 2 or ISO 27001 goes first based on your buyer geography and enterprise pipeline.

Share this article:

Ready to build your security program?

See how easy it can be.