SOC 2 Explained
- SOC 2 is a report written by an independent accounting firm about how a company protects customer data.
- It exists because large buyers stopped trusting supplier self-assessments and wanted an outside opinion.
- The auditor does not give a score or a pass mark. They describe the controls and state an opinion.
- Security is the only part every report covers. Four other areas are added by choice.
- "We have SOC 2" can mean very different things. The report itself is the only way to know which.
What SOC 2 is
SOC 2 is a report about trust. A company that holds other people's data pays an independent accounting firm to examine how it protects that data, and the firm writes up what it found. Buyers read the report before deciding whether to hand over their information.
That is the whole idea. Everything else is detail about how the examination works.
Why does SOC 2 exist?
Before SOC 2, a large company buying software had two options. Believe what the supplier said about its own security, or send its own team in to check. Believing was unreliable. Checking was expensive, and it did not scale when a company had four hundred suppliers.
SOC 2 solved that by having one independent firm do the examination once, and the resulting report shared with every buyer who asks. The buyer gets an outside opinion. The supplier does the work once instead of forty times.
The framework comes from the American Institute of Certified Public Accountants, the professional body for accountants in the United States. That is why the examination has to be done by an accounting firm rather than a security firm, and why the output is a report rather than a certificate.
What does the auditor actually look at?
The auditor works through a set of criteria and asks, for each one, whether the company has a control that meets it and whether that control works.
In plain terms, they are asking questions like these. Who can get into the systems, and how do you know that list is still correct? When someone leaves the company, how quickly does their access disappear, and can you show me? When code changes, who approves it, and where is the record? If something goes wrong, what happens, and has that ever been tested? Which outside companies handle your data, and when did you last check them?
For each answer, the auditor wants evidence rather than description. A policy stating that access is reviewed quarterly is a claim. Four dated review records are evidence.
What comes out at the end?
A written report, typically forty to eighty pages. It contains a description of the company's systems, management's own assertion about its controls, a list of the controls, the tests the auditor performed, the results of those tests, and the auditor's opinion.
There is no score and no pass mark. There is an opinion, which is normally unqualified, meaning the auditor found no significant problems. Where the auditor did find something, it appears in the report as an exception, described plainly.
Reports are shared under a confidentiality agreement rather than published, which is why you cannot look up a company's SOC 2 report the way you can look up an ISO certificate.
The five areas a report can cover
| Area | The question it answers |
|---|---|
| Security | Is the data protected from people who should not have it? |
| Availability | Is the service up when you promised it would be? |
| Processing integrity | Does the system process data correctly and on time? |
| Confidentiality | Is information marked confidential actually kept that way? |
| Privacy | Is personal information handled properly across its life? |
Security appears in every SOC 2 report. The other four are added when a customer asks or the company has committed to them contractually. Most first reports cover Security alone, which is entirely normal and not a weakness.
What "we have SOC 2" can mean
This phrase covers a wide range, and the difference matters when you are the one relying on it.
It might mean a Type 1 report, which examined the design of the controls on one particular day. It might mean a Type 2 report, which examined whether those controls operated across several months. It might mean a report covering a system that is not the one you are buying. It might mean a report that is two years old.
If you are on the buying side, ask for the report itself, check the period it covers, check which systems are in scope, and read the exceptions section. If you are on the selling side, expect sophisticated buyers to do exactly that.
How SOC 2 compares to ISO 27001
The two are often mentioned together and they work differently.
ISO 27001 produces a certificate. An accredited body assesses your information security management system, and if you meet the standard you get a certificate valid for three years with annual check-ups. It is recognised worldwide and you can publish it.
SOC 2 produces a report covering a past period. It carries most weight with American buyers, and it is shared privately.
Neither replaces the other, and many companies hold both. Because the underlying controls overlap heavily, the second one costs far less than the first. Our ISO 27001 service page sets out how they run together.
What to do next
If a customer has asked you for SOC 2, find out which report they need and which systems they care about before doing anything else. That answer sets your cost and your timetable.
Our free readiness diagnostic gives a first view of where you stand, and the SOC 2 service page explains how a programme runs from start to report.
References
FAQ
Is SOC 2 a certification?
No. It produces a report and an opinion, not a certificate. Only a licensed accounting firm can issue one.
Who reads a SOC 2 report?
The security and procurement teams at companies buying your software or services, and sometimes their auditors and insurers.
Can I see another company's SOC 2 report?
Only if they give it to you, normally under a confidentiality agreement. Reports are not published.
Does SOC 2 mean a company has never been breached?
No. It means an independent firm examined the controls described and found they operated as described over the period covered.
How often is it repeated?
Annually. Most buyers treat a report older than twelve months as out of date.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act, from first assessment to report, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.