HackproofHacks
Compliance, explained plainly

What Is SOC 2? A Plain-English Guide for Founders

SOC 2 is an audit report, not a certification. An independent auditor examines your company's security controls against a framework called the Trust Services Criteria and states, in writing, whether those controls are properly designed (a Type I report) or actually worked over a period of months (a Type II report). Most B2B software companies pursue it because enterprise customers require the report before they'll sign a contract, not because a regulator demands it.

Nobody sets out wanting a SOC 2 report. It shows up as a line item in an enterprise deal: a prospect's security team asks for it during procurement, and a compliance term that sounded abstract becomes the thing blocking your biggest deal of the quarter.

The short version: SOC 2 isn't a checklist you complete once, and it isn't issued by a government body. It's an audit opinion, renewed on a schedule, backed by evidence your team has to keep producing.

What SOC 2 actually certifies

SOC 2 stands for System and Organization Controls 2, a framework maintained by the AICPA, the same body that oversees financial auditing standards in the US. Unlike ISO 27001, which is a certification you either hold or don't, SOC 2 produces a report: a licensed CPA firm examines your controls and writes an opinion on whether they meet the standard. There's no pass-or-fail badge to display. The report itself is the deliverable, and you share it directly with customers under NDA.

The controls are organized around five Trust Services Criteria, though almost every company is only assessed against the first one plus whichever others apply to its business:

  • Security (required for every SOC 2 report): access controls, encryption, vulnerability management, and incident response. This is the criterion that includes the penetration-testing expectation.
  • Availability: uptime commitments and disaster recovery, relevant if you have an SLA.
  • Processing integrity: whether your system processes data completely, accurately, and on time, mostly relevant for payment or transaction-processing platforms.
  • Confidentiality: how you protect data designated as confidential, beyond personal information specifically.
  • Privacy: how you collect, use, and dispose of personal information, overlapping with GDPR and similar regulations.

Type I vs Type II: the difference that actually matters

A Type I report is a snapshot: the auditor confirms your controls are designed correctly as of a single date. A Type II report covers a window, usually three to twelve months, and confirms those controls actually operated the way you said they would across that entire period.

Enterprise buyers almost always want Type II. A Type I report proves you wrote a good policy; a Type II report proves you followed it. Most companies start with a Type I to get a report in hand quickly, then move to Type II once they have a few months of evidence to show.

Where a penetration test fits in

SOC 2 does not contain a line that says "run a penetration test." It asks, under the Security criterion, whether you identify vulnerabilities and act on them (control CC7.1) and whether you monitor for new ones (CC4.1). In practice, almost every auditor treats an annual independent penetration test as the cleanest way to provide that evidence, because an automated scan cannot demonstrate the kind of hands-on testing the criteria describe.

That's a separate engagement from the audit itself. Your auditor examines your controls, and a penetration tester, a different party for independence, provides one of the pieces of evidence the auditor reviews.

Do you need it yet

If an enterprise prospect's security team has already asked for it, you need it now, because the sales cycle won't wait for a Type II report to mature. If you're pre-revenue or only selling to small businesses that never ask for a security review, it's reasonable to wait, since a SOC 2 program has a real ongoing cost in engineering time and audit fees.

The middle case is the common one: you are closing your first few mid-market or enterprise deals and can see this becoming a recurring ask. Starting the readiness work now, before it is blocking a live deal, is what turns SOC 2 from a fire drill into routine.

Frequently asked questions

Is SOC 2 legally required?

No. SOC 2 is not a legal or regulatory requirement in the way GDPR or HIPAA can be. Companies pursue it because customers and procurement teams require it as a condition of doing business, which makes it commercially necessary without being a legal mandate.

How long does SOC 2 take to complete?

A Type I report can often be produced in six to ten weeks once controls are in place, since it only requires a point-in-time review. A Type II report requires an observation period, typically three to twelve months, before the audit can even start, so the realistic timeline from a standing start to a Type II report is closer to six to nine months.

What's the difference between SOC 2 and ISO 27001?

SOC 2 is common in the US and produces an audit report you share under NDA; ISO 27001 is an international standard and results in an actual certification you can display publicly. Many companies pursuing global enterprise customers eventually hold both, but SOC 2 is usually the faster, cheaper first step for a US-based SaaS company.

Who performs a SOC 2 audit?

Only a licensed CPA firm can issue a SOC 2 report, since it's governed by AICPA auditing standards. A penetration tester is a separate party who provides supporting evidence, not the auditor of record.

Do we need a penetration test before or during the SOC 2 audit?

Before, and ideally with enough lead time to fix what it finds. Auditors want to see evidence that vulnerabilities were identified and remediated within the observation period, so a penetration test scheduled right before the audit window closes leaves no time to fix anything it finds.

Related guides

Related services

Ready to scope your test?

Book a free 30-minute scoping call. We agree the scope, timeline, and a fixed price up front, with no obligation and no surprises for your deadline.