Hael
Book a meeting
SOC 2 · Overview

SOC 2 compliance

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • SOC 2 compliance runs on an annual cycle: scope, build, observation period, examination, report, repeat.
  • Type 1 examines design on one date. Type 2 examines operation over a period, and is what buyers want.
  • First-year cost typically falls between roughly $30,000 and $150,000, of which the auditor's fee is usually the smaller part.
  • A first Type 2 report normally arrives nine to twelve months after the programme starts.
  • The recurring work is smaller than the build, but it is the part that decides whether year two is cheap or expensive.

SOC 2 compliance as a cycle

SOC 2 compliance is a cycle rather than a project. You define a scope, build controls that meet the criteria, run them for a period while evidence accumulates, have an independent accounting firm examine that period, receive a report, and then begin the next period. This overview covers each stage and the numbers attached to it.

If you want the plain explanation of what SOC 2 is rather than how to run it, that is in SOC 2 Explained.

The criteria

Five categories, called the Trust Services Criteria, published by the American Institute of Certified Public Accountants.

CriterionCoversIn every report?
SecurityGovernance, risk assessment, access control, change management, monitoring, incident responseYes
AvailabilityUptime commitments, backup, disaster recoveryOnly if selected
Processing integrityComplete, accurate, timely and authorised processingOnly if selected
ConfidentialityProtection of information designated confidentialOnly if selected
PrivacyCollection, use, retention and disposal of personal informationOnly if selected

The criteria have been stable since 2017. The supporting guidance, known as the points of focus, was updated in October 2022 to reflect newer technologies and threats. The criteria themselves did not change.

The two report types

A Type 1 report examines whether the controls were suitably designed on one specific date. A Type 2 report examines whether they operated as described over a period, usually three to twelve months.

Type 2 is the standard expectation in enterprise procurement, because a control that exists on paper is not the same as a control that runs every week. Type 1 has one good use: when a deal is live and the buyer will accept it as evidence of a real programme while the Type 2 observation period runs.

Cost

ComponentTypical first-year range
Auditor fee, Type 1$5,000 to $25,000
Auditor fee, Type 2$15,000 to $60,000
Readiness or gap assessment$5,000 to $25,000
Remediation$5,000 to $30,000 or more
Penetration testing$4,000 to $25,000
Compliance platform$7,500 to $25,000 a year
Total, small to mid-sized companyRoughly $30,000 to $150,000

Internal team time is frequently the largest single cost and rarely appears in the budget. Second-year totals typically fall by around a third, provided the controls kept operating.

Timeline

Six to ten weeks to be ready for a Type 1 examination if the environment is straightforward. Nine to twelve months for a first Type 2 report, because the observation period runs forward and cannot be compressed once it has started.

The observation period length is a genuine choice. Three months is the shortest most auditors accept and produces a report soonest. Six months tests quarterly controls more fairly. Twelve is standard once a company is in an established annual cycle.

Who does the work

Three separate roles, frequently confused in sales conversations.

A compliance platform monitors configuration and collects evidence automatically. It produces a list of what is missing.

A consultancy sets the scope, designs and implements the controls, writes the policies, establishes the evidence framework, manages the project and prepares the company for examination. It cannot issue the report.

A licensed accounting firm performs the examination and issues the report. It cannot prepare you for its own examination.

Most companies use all three. What each of them does, and when hiring is worth it, is covered in SOC 2 consultancy services.

What goes wrong

The failure patterns are consistent and almost none of them are technical.

Scope drawn too wide, raising cost without helping the sale. Scope drawn too narrow, producing a report the buyer rejects. Policies describing a company that does not exist, which surfaces in the first interview. Evidence assembled in the final weeks of a period it was meant to span, which is exactly what Type 2 sampling detects. Penetration testing left until late. And most commonly, no single person owning the programme, so the task list grows while the audit date stays fixed.

After the report

The day the report is issued, the next period has already started. Controls that stop in month two will appear in next year's examination.

Buyers will also read the report and ask questions from it. Someone needs to answer those, from the same evidence base, without a scramble each time. That ongoing work is what our continuous governance and assurance service covers, and it is the difference between a cheap second year and an expensive one.

What to do next

Get your buyer's requirement in writing: report type, systems in scope, real deadline. Then establish where you actually stand.

Our free readiness diagnostic gives a first view, our readiness and gap assessment produces the detailed picture for a fixed fee, and the SOC 2 service page sets out how we run the full programme.

References

FAQ

How long does SOC 2 compliance take?

Six to ten weeks to be ready for a Type 1. Nine to twelve months for a first Type 2, driven by the observation period.

How much does SOC 2 compliance cost?

Roughly $30,000 to $150,000 in the first year for a small to mid-sized company, with the auditor's fee usually the smaller part.

Which report do enterprise buyers want?

Type 2, almost always. Type 1 is accepted in some cases as an interim step with a commitment to follow it.

Do we need a compliance platform?

Not strictly, but most companies find it removes enough manual evidence collection to justify the subscription.

What happens if the auditor finds a problem?

It appears in the report as an exception, described plainly. An exception is not a failure, but buyers read that section, so it is worth avoiding where you can.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act. Every engagement has a named practitioner and an agreed scope, timetable and fee. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.