SOC 2
SOC 2 — System and Organization Controls
Prove to customers that you handle their data securely — the report US enterprises ask for first.
Issuer
AICPA
Region
Global (US-origin)
Report types
Type I / Type II
Basis
Trust Services Criteria
Overview
What is SOC 2?
SOC 2 is an independent audit, defined by the AICPA, that reports on how a service organization manages customer data. Rather than a fixed checklist, it evaluates your controls against five Trust Services Criteria, and an accredited CPA firm issues the report.
There are two kinds. A Type I report assesses whether your controls are designed correctly at a single point in time; a Type II report tests that they operated effectively over a period — typically three to twelve months. Type II is what most enterprise buyers expect to see.
Who needs it: Any SaaS or service company that stores, processes, or transmits customer data — especially when selling to US enterprises, where a SOC 2 report is often a precondition for closing the deal.
Inside the framework
The five Trust Services Criteria
Security (Common Criteria)
The mandatory baseline: protection against unauthorized access, covering access control, change management, and risk mitigation.
Availability
Systems are available for operation and use as committed — uptime, performance monitoring, and disaster recovery.
Processing Integrity
Processing is complete, valid, accurate, timely, and authorized.
Confidentiality
Information designated as confidential is protected throughout its lifecycle.
Privacy
Personal information is collected, used, retained, and disposed of in line with your privacy notice.
With RegShield
Get SOC 2-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right SOC 2 controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for SOC 2 is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your SOC 2 readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Is SOC 2 a certification?
No. SOC 2 results in an attestation report from a licensed CPA firm, not a pass/fail certificate. Buyers review the report itself.
Type I or Type II?
Start with Type I to show your controls are designed correctly, then pursue Type II to prove they operate over time. Most enterprise customers want Type II.
How long does it take?
Readiness can take a few weeks to a few months depending on your starting posture; a Type II observation window then runs three to twelve months. RegShield shortens the readiness phase by mapping your evidence automatically.