What Is SOC 2? A Practical Guide for SaaS Companies
Published September 24, 2026
By Kelvin O. Medina
SOC 2 often enters a SaaS roadmap through a customer review. A prospect asks for a report or a renewal needs stronger evidence. The useful question is not “How fast can we get certified?” It is “What system and customer commitments should the report cover?”
What SOC 2 is and what it is not
SOC 2 examines service-organization controls relevant to security, availability, processing integrity, confidentiality, or privacy. An independent CPA firm issues an opinion. The report includes management's description and assertion, tests, and results for specified users.
SOC 2 is not a certification, incident guarantee, or universal checklist. The organization completes an examination and receives an independent CPA firm's report. The AICPA maintains SOC 2 resources and illustrative reports.
Type I and Type II answer different questions
| Report type | What it addresses | Buyer implication |
|---|---|---|
| Type I | Whether controls were suitably designed as of a specified date. | Useful evidence of control design, but not evidence that controls operated throughout a period. |
| Type II | Whether controls were suitably designed and operated effectively over a defined period. | Provides evidence about operation over time, including the auditor's tests and results. |
Type II requires an observation period. Timing depends on scope, control maturity, remediation, the agreed period, auditor availability, and evidence. Agree dates before customer commitments.
Choose Trust Services Criteria from real commitments
Security, often called the common criteria, is included in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are added when relevant to the service and its customer commitments. The AICPA's Trust Services Criteria provide the authoritative framework.
Selection should follow the product. A payments platform may need Confidentiality for merchant data and Processing Integrity for transaction commitments. SaaS uptime targets may support Availability. Personal data does not automatically require Privacy; use it when the examination addresses privacy commitments. Unnecessary categories add work without improving assurance.
Readiness and examination are separate jobs
Readiness defines scope, maps controls, identifies gaps, and builds evidence. Internal teams or a consultant can perform it. An independent CPA firm examines controls and issues the opinion.
ControlSolid provides readiness and remediation, not SOC 2 reports or audit opinions. The CPA firm remains independent, and management remains responsible for its controls and assertion.
Practical first steps
- Confirm the trigger. Ask whether the buyer needs Type I or Type II, which product must be covered, and what date matters.
- Define the system. Identify the service, infrastructure, people, data, software, and third parties supporting customer commitments.
- Select criteria. Start with Security, then add categories supported by contracts, product behavior, or customer needs.
- Map controls. Name each control's owner, frequency, system of record, and evidence.
- Test before the window. Confirm controls operate as described and produce evidence.
- Select the CPA firm early. Align scope, report type, period, fees, and handoff.
Common readiness gaps
- Scope misses the product sold. Shared infrastructure, support, or a critical subprocess is absent.
- Policies describe an imaginary process. A review has no owner, schedule, or evidence.
- Access evidence is incomplete. Lifecycle, privileged-access, and review records do not reconcile.
- Emergency changes bypass controls. Hotfixes, infrastructure, or database work lack the traceability of normal changes.
- Vendor review stops at an inventory. Risk decisions, safeguards, and follow-up actions are undocumented.
- Evidence starts too late. Year-end screenshots do not show consistent operation throughout the period.
How to choose the independent CPA firm
Confirm the firm is licensed, independent, experienced with similar SaaS systems, and in the applicable peer-review program. Ask about staffing, sampling, exceptions, scope, and handoff.
Do not select only on speed. A report with incomplete scope, irrelevant criteria, or weak evidence will not solve the original procurement need.
Plan the next step around the buyer need
Record the report type, scope, criteria, and deadline. Readiness should produce an agreed boundary, control owners, gap register, priorities, and evidence calendar.
ControlSolid's SOC 2 readiness service helps SaaS teams define scope, strengthen controls, prepare evidence, and hand off to an independent CPA firm. For related technical evidence, see our guide to penetration test attestation letters and our broader security readiness and gap assessment work.
References
- AICPA & CIMA: SOC 2 Trust Services Criteria resources
- AICPA 2017 Trust Services Criteria, with revised points of focus (2022)
- AICPA illustrative service auditor's SOC 2 Type II report
This article is general readiness guidance, not an audit opinion or guarantee of a particular examination result. The independent CPA firm determines examination scope, procedures, and opinion.