Security Assurance

What Is SOC 2? A Practical Guide for SaaS Companies

Published September 24, 2026

By Kelvin O. Medina

SOC 2 often enters a SaaS roadmap through a customer review. A prospect asks for a report or a renewal needs stronger evidence. The useful question is not “How fast can we get certified?” It is “What system and customer commitments should the report cover?”

What SOC 2 is and what it is not

SOC 2 examines service-organization controls relevant to security, availability, processing integrity, confidentiality, or privacy. An independent CPA firm issues an opinion. The report includes management's description and assertion, tests, and results for specified users.

SOC 2 is not a certification, incident guarantee, or universal checklist. The organization completes an examination and receives an independent CPA firm's report. The AICPA maintains SOC 2 resources and illustrative reports.

Type I and Type II answer different questions

Report typeWhat it addressesBuyer implication
Type IWhether controls were suitably designed as of a specified date.Useful evidence of control design, but not evidence that controls operated throughout a period.
Type IIWhether controls were suitably designed and operated effectively over a defined period.Provides evidence about operation over time, including the auditor's tests and results.

Type II requires an observation period. Timing depends on scope, control maturity, remediation, the agreed period, auditor availability, and evidence. Agree dates before customer commitments.

Choose Trust Services Criteria from real commitments

Security, often called the common criteria, is included in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are added when relevant to the service and its customer commitments. The AICPA's Trust Services Criteria provide the authoritative framework.

Selection should follow the product. A payments platform may need Confidentiality for merchant data and Processing Integrity for transaction commitments. SaaS uptime targets may support Availability. Personal data does not automatically require Privacy; use it when the examination addresses privacy commitments. Unnecessary categories add work without improving assurance.

Readiness and examination are separate jobs

Readiness defines scope, maps controls, identifies gaps, and builds evidence. Internal teams or a consultant can perform it. An independent CPA firm examines controls and issues the opinion.

ControlSolid provides readiness and remediation, not SOC 2 reports or audit opinions. The CPA firm remains independent, and management remains responsible for its controls and assertion.

SOC 2 readiness and independent examination pathManagement and its readiness support define scope, improve controls, and prepare evidence. An independent CPA firm then examines the system and issues the SOC 2 report. Type I covers a specified date, while Type II covers operation throughout a defined period.Two distinct responsibilitiesReadiness workManagement, internal teams, and readiness support• Define system scope and criteria• Strengthen controls and remediate gaps• Build reliable evidenceHandoffIndependent CPA examinationPerformed and reported by an independent CPA firm• Evaluate the description and assertion• Test controls and document results• Issue the SOC 2 report and opinionChoose the report type for the buyer needType IControls as of a specified dateType IIControls operating over a defined period
Readiness prepares the organization and its evidence. The independent CPA firm performs the examination and issues the report and opinion.

Practical first steps

  1. Confirm the trigger. Ask whether the buyer needs Type I or Type II, which product must be covered, and what date matters.
  2. Define the system. Identify the service, infrastructure, people, data, software, and third parties supporting customer commitments.
  3. Select criteria. Start with Security, then add categories supported by contracts, product behavior, or customer needs.
  4. Map controls. Name each control's owner, frequency, system of record, and evidence.
  5. Test before the window. Confirm controls operate as described and produce evidence.
  6. Select the CPA firm early. Align scope, report type, period, fees, and handoff.

Common readiness gaps

  • Scope misses the product sold. Shared infrastructure, support, or a critical subprocess is absent.
  • Policies describe an imaginary process. A review has no owner, schedule, or evidence.
  • Access evidence is incomplete. Lifecycle, privileged-access, and review records do not reconcile.
  • Emergency changes bypass controls. Hotfixes, infrastructure, or database work lack the traceability of normal changes.
  • Vendor review stops at an inventory. Risk decisions, safeguards, and follow-up actions are undocumented.
  • Evidence starts too late. Year-end screenshots do not show consistent operation throughout the period.

How to choose the independent CPA firm

Confirm the firm is licensed, independent, experienced with similar SaaS systems, and in the applicable peer-review program. Ask about staffing, sampling, exceptions, scope, and handoff.

Do not select only on speed. A report with incomplete scope, irrelevant criteria, or weak evidence will not solve the original procurement need.

Plan the next step around the buyer need

Record the report type, scope, criteria, and deadline. Readiness should produce an agreed boundary, control owners, gap register, priorities, and evidence calendar.

ControlSolid's SOC 2 readiness service helps SaaS teams define scope, strengthen controls, prepare evidence, and hand off to an independent CPA firm. For related technical evidence, see our guide to penetration test attestation letters and our broader security readiness and gap assessment work.

References

This article is general readiness guidance, not an audit opinion or guarantee of a particular examination result. The independent CPA firm determines examination scope, procedures, and opinion.

Related service

SOC 2 Readiness →

Contact Us