Playbook · Track 1 · Lesson 1 of 10 · 3 min

What is SOC 2? A plain guide for startups

Short answer

SOC 2 is a report a licensed CPA firm issues after examining a company's controls against the AICPA's Trust Services Criteria. Startups get one because customers ask for it in security reviews. It is not a certificate and not a law.

What exactly is a SOC 2 report?

System and Organization Controls, or SOC, is a suite of service offerings that CPAs may provide, set out by the AICPA. SOC 2 is the one most software companies meet first. The AICPA's guide for it is titled 'SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy'. That title says most of what you need: a CPA firm examines your controls, and reports on them against one or more of five categories.

The finished report usually contains the auditor's opinion, a written assertion from your management, a description of your system, and a list of your controls. A Type II report also lists the tests the auditor ran and the results.

Why do customers ask a startup for SOC 2?

A customer handing you its data wants to know how you protect it. Instead of sending every supplier a long questionnaire and hoping the answers are accurate, many buyers ask for a SOC 2 report because a CPA firm has examined the claims. For a startup selling to larger companies, the request often arrives from a procurement or security team during a deal, which is why so many first audits start with a deadline.

What is SOC 2 not?

It is not a law. No regulation requires a SOC 2 report in general, although contracts often do. It is not a certification in the ISO sense: there is no certificate and no pass mark, only an auditor's opinion in a report. And it is not something software can issue. Compliance tools help you prepare, collect evidence and manage the audit, but the report comes from a CPA firm.

What does a SOC 2 cover?

Security is always included. Availability, Processing Integrity, Confidentiality and Privacy are optional, and you choose them based on what you promise customers. The next lesson explains how to choose. You also decide the scope: which product, systems, people and processes the report describes.

Who can see the report?

A SOC 2 report is usually shared with customers and prospects under a nondisclosure agreement, not published. Many companies put a summary and a request button on a trust center page so buyers can ask for it. A SOC 3 report is the general-use version meant for public sharing.

What does a startup need to decide first?

Three things: which Trust Services Criteria to include, whether to start with a Type I or go straight to a Type II, and who will run the work. The Playbook covers each in turn, and the path finder turns the third question into a shortlist.

Further reading

What should you read next?

Next lesson · 2 of 10

The SOC 2 Trust Services Criteria: which to include in your first audit

Questions founders ask

Is SOC 2 a certification?

No. It is an attestation report with an auditor's opinion. People say 'SOC 2 certified', but there is no certificate.

Who can issue a SOC 2 report?

A licensed CPA firm. Software vendors can help you prepare or arrange an auditor, but they cannot issue the report unless they are, or include, a CPA firm.

Do we need SOC 2 if we have ISO 27001?

Sometimes. Some customers accept ISO 27001; many buyers of business software ask for SOC 2 specifically. Ask the customer which report they accept.