By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 18, 2026
Quick answer: SOC 2 compliance for a business is demonstrated through an audit, developed by the American Institute of Certified Public Accountants, that evaluates whether a service organization’s controls meet defined criteria for security, availability, processing integrity, confidentiality, and privacy. It is the most widely required security certification for SaaS companies and service providers selling to enterprise customers in North America. A SOC 2 Type II report, covering a defined observation period that most often runs six to twelve months, is what most enterprise procurement teams are asking for when they say they need to see your security certification.
Key Takeaways
- SOC 2 is not a standard you comply with; it is an audit that a qualified CPA firm conducts to attest that your controls meet the Trust Services Criteria. The report is the attestation, and the report is what your customers want to see.
- Type I reports attest that controls are suitably designed at a point in time. Type II reports attest that controls were suitably designed and operating effectively over a defined period, commonly six to twelve months. Enterprise customers almost universally require Type II; Type I is a stepping stone for organizations that are not yet ready for a Type II observation period.
- The Security trust services criterion is required for all SOC 2 engagements. Availability, processing integrity, confidentiality, and privacy are optional criteria selected based on the commitments the service organization makes to its customers. Most organizations start with Security only; SaaS platforms handling health data or financial data typically add Availability and Confidentiality.
- The observation period for a Type II is the most demanding aspect of the engagement. Controls must be consistently implemented throughout the period, not just at the time of the audit. Evidence of consistent operation, not point-in-time snapshots, is what the auditor reviews.
- Common SOC 2 failures are almost always preventable with readiness preparation: policies not updated to reflect current practices, access reviews not documented with sufficient detail, vendor management not covering all service providers in scope, and change management logs missing required fields.
What SOC 2 Actually Is
SOC 2 (System and Organization Controls 2) is a reporting framework developed by the American Institute of Certified Public Accountants for service organizations, companies that provide technology or data processing services to other businesses. The framework evaluates whether a service organization’s controls meet the Trust Services Criteria, a set of principles and criteria published by the AICPA covering security, availability, processing integrity, confidentiality, and privacy. It is worth being precise about the language: what people call SOC 2 certification is technically an attestation, not a certification, but the search term and the sales conversation both use “certification” interchangeably.
A SOC 2 report is not a certification in the traditional sense. It is an attestation by an independent CPA firm that the service organization’s controls, as described in the report, were suitably designed (Type I) or suitably designed and operating effectively (Type II) during the observation period. The report is addressed to user entities, meaning the customers of the service organization, and it gives them an independent, structured view of the service organization’s control environment without requiring each customer to conduct its own security assessment.
This is why enterprise customers require SOC 2 reports. A large enterprise that relies on dozens or hundreds of software vendors and service providers cannot practically conduct a full security assessment of every vendor independently. The SOC 2 report is the substitute: an independent, standardized assessment that allows procurement teams to evaluate vendor security posture through a recognized format. For SaaS companies in particular, meeting the SOC 2 requirements SaaS buyers expect has become a baseline condition of selling upmarket rather than a differentiator.
The Five Trust Services Criteria
Security (CC criteria)
The Security criterion is required for all SOC 2 engagements and covers the protection of information and systems from unauthorized access, use, disclosure, modification, or destruction. The Security criteria address logical and physical access controls, system operations including change management and incident management, risk assessment, monitoring activities, and the change management processes that maintain security throughout the system lifecycle. Most organizations start their SOC 2 journey with Security as the only in-scope criterion.
Availability
The Availability criterion covers whether the system is available for operation and use as committed or agreed. It addresses the monitoring of system capacity and performance, incident and problem management processes that affect availability, and the backup and recovery procedures that restore availability after disruption. Organizations that make contractual commitments about uptime or service availability typically include Availability in their scope.
Processing integrity
The Processing integrity criterion covers whether the system processes data completely, accurately, timely, and only as authorized. It is most relevant for organizations that perform transaction processing or data transformation on behalf of customers, including financial technology companies, payment processors, and data analytics platforms.
Confidentiality
The Confidentiality criterion covers whether information designated as confidential is protected as committed or agreed. It addresses data classification, encryption of confidential data in transit and at rest, and the access controls that limit confidential data to authorized parties. Organizations that handle proprietary customer data, trade secrets, or other confidential business information in the course of providing their service typically include Confidentiality.
Privacy
The Privacy criterion covers the collection, use, retention, disclosure, and disposal of personal information. It addresses notice and consent, individual rights, third-party disclosures, and the safeguards protecting personal information. Organizations that collect significant volumes of personal information, particularly sensitive personal information, may include Privacy in their scope, and often run it alongside a broader privacy risk management program.
Type I vs. Type II: What the Difference Means in Practice
A SOC 2 Type I report attests that the service organization’s description of its system is fairly presented and that the controls included in that description are suitably designed to meet the applicable trust services criteria as of a specific date. It is a point-in-time assessment. A SOC 2 Type II report attests the same design adequacy and additionally attests that the controls operated effectively throughout the observation period. The AICPA does not mandate a fixed minimum length for that period; in practice it runs from three to twelve months, with a first Type II often covering six months and annual renewals covering twelve.
The practical significance of this difference is substantial. Suitable design tells the reader that the controls, if they were followed as described, would meet the criteria. Operating effectiveness tells the reader that the controls were actually followed consistently throughout the period. Enterprise customers understand this distinction well: a Type I report tells them what the service organization intends to do; a Type II report tells them what it actually did over an extended period. Most enterprise procurement requirements specify Type II.
For organizations pursuing SOC 2 for the first time, the typical path is to achieve Type I first, which confirms that the control design is adequate, and then begin the Type II observation period. Some organizations begin the Type II observation period directly if they have confidence that their controls are both well-designed and consistently operating. A compliance readiness audit is particularly important for this direct-to-Type-II approach, because any lapse in control operation during the observation period will appear in the Type II report.
What Consistent Control Operation Actually Requires
The Type II observation period is where most SOC 2 efforts run into difficulty. Controls that are implemented and functioning at the start of the observation period can fall short over the following months due to personnel changes, system changes, operational pressure, or simple human error. The auditor reviews evidence of control operation throughout the period, not just at audit time, which means consistent execution over an extended period rather than a burst of compliance activity in the weeks before fieldwork begins. Maintaining that evidence is exactly what a year-round audit readiness discipline is built to do.
The controls that most frequently show operating effectiveness gaps during Type II audits are access reviews, where quarterly or annual reviews are required but evidence of completion is incomplete or missing; change management, where change records lack required approvals or pre-implementation reviews; vendor management, where new vendors were onboarded during the period without going through the due diligence process required by policy; security awareness training, where completion tracking does not cover all required employees; and incident management, where incidents were handled but not documented in the format required by policy.
A readiness audit conducted before the Type II observation period begins confirms that the controls are not only well-designed but that the evidence capture processes are in place to demonstrate consistent operation throughout the period. Armour Cybersecurity’s compliance readiness engagements address both design adequacy and evidence readiness for SOC 2 Type I and Type II.
Frequently Asked Questions
How long does it take to get a SOC 2 Type II report?
The timeline from starting preparation to receiving the Type II report is typically twelve to eighteen months for organizations starting from a low maturity baseline. This includes the readiness assessment and gap remediation, typically two to four months, followed by the Type II observation period, commonly six to twelve months with three months the practical floor, followed by the formal audit fieldwork and report issuance, typically two to three months. Organizations with a more mature control environment that begin the observation period immediately after a readiness audit can complete the process in eight to twelve months.
Who can perform a SOC 2 audit?
SOC 2 audits must be conducted by a licensed CPA firm with experience in SOC engagements. The firm must be independent of the service organization being audited. The CPA firm issues the attestation report and is responsible for the opinion expressed in it. Advisory firms like Armour Cybersecurity assist with readiness preparation but do not conduct the formal audit or issue the attestation report. Organizations engage a CPA firm for the formal audit and may engage a compliance advisory firm separately for readiness work, remediation support, and audit coordination. Keeping the firm that builds or remediates the controls separate from the firm that issues the report is what protects the independence the report depends on.
What is in scope for a SOC 2 audit?
The scope of a SOC 2 audit is defined by the system description: the infrastructure, software, people, procedures, and data that comprise the service organization’s system for providing the service under examination. Scope definition is one of the most consequential decisions in the SOC 2 process. A scope that is too narrow may not satisfy the customer’s requirement if it excludes systems that are integral to the service. A scope that is too broad includes systems and processes that require controls and evidence beyond what the organization has prepared. A readiness audit helps define the scope accurately before the formal audit, preventing surprises during fieldwork.
Do we need a SOC 2 if we already have ISO 27001?
ISO 27001 and SOC 2 serve different purposes and are recognized in different markets. ISO 27001 is an international standard with global recognition, particularly strong in Europe, Asia Pacific, and for organizations operating across multiple jurisdictions. SOC 2 is developed by the American Institute of Certified Public Accountants and is the dominant requirement for enterprise customers in North America, particularly in the US technology sector. Many organizations that sell globally hold both. The controls required by the two frameworks overlap significantly, which means an organization with ISO 27001 in place is well-positioned to pursue SOC 2, and a multi-framework readiness engagement can map controls across both simultaneously.
What happens if a customer asks for our SOC 2 report and we do not have one?
The typical outcome in an enterprise B2B sales context is that the deal stalls while the customer evaluates alternatives or waits for the certification, or the deal proceeds with contractual security obligations and a commitment to provide the SOC 2 report within a defined timeframe. Neither outcome is ideal: a stalled deal may be lost, and a contractual commitment to deliver the report creates a hard deadline that may not align with the certification timeline. Organizations that are actively pursuing SOC 2 can sometimes satisfy the immediate customer requirement with a letter of engagement from their assessor, a bridge security questionnaire, or a Type I report while the Type II observation period is underway.
The Bottom Line
SOC 2 is not a badge you switch on; it is an independent CPA attestation that your controls met the Trust Services Criteria over time, and for most SaaS and service businesses it has become the price of selling to the enterprise. The Security criterion is mandatory, the other four are chosen against the commitments you make to customers, and the Type II observation period, the part most teams underestimate, is where good design has to become consistent operation. The organizations that get a clean report on schedule are the ones that prepared for it: scope confirmed, evidence captured continuously, and gaps closed before the observation period rather than during fieldwork. A structured compliance readiness engagement is what turns SOC 2 from a scramble into a predictable outcome.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



