Hael
Book a meeting
SOC 2 · Introduction

What Is SOC 2 Compliance?

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • SOC 2 compliance means an independent accounting firm has examined your controls and issued a report on them.
  • Strictly there is no compliant or non-compliant state. There is a report, covering a period, with or without exceptions.
  • Compliance is a continuing condition, not an event. The controls have to keep operating between examinations.
  • Nothing in law requires it. It is a commercial requirement created by buyers.
  • The obligations it creates are internal: named owners, recurring controls, retained evidence.

What SOC 2 compliance means

SOC 2 compliance means a licensed accounting firm has examined how your organisation protects customer data and has issued a written report on what it found. In everyday use, saying a company is SOC 2 compliant means it holds a current report with no significant exceptions.

The phrase is slightly loose, because SOC 2 has no formal compliant or non-compliant status. There is a report, it covers a defined period, and it either contains exceptions or it does not. That distinction matters more than it sounds, because it shapes what you are actually committing to.

What being compliant actually requires

Four things have to be true at once, and only the last of them is visible from outside.

  • You have defined a scope: the systems and services being examined, and the criteria being applied.
  • You have controls in place that meet each criterion in that scope.
  • Those controls operate consistently, and operating them leaves a dated record.
  • An independent accounting firm has examined all of the above and issued its opinion.

The third one is where most of the ongoing work sits, and it is the one that continues after the report arrives.

What obligations does compliance create inside the company?

ObligationWhat it means in practice
Named ownershipEach control has a person responsible for operating it, and that name is known
Recurring operationAccess reviews, vendor reviews, change approvals and similar controls run on a schedule and keep running
Retained evidenceEach occurrence leaves a dated record that survives, because the auditor samples across the period
Scope maintenanceNew systems, new subprocessors and new environments are assessed against the existing scope rather than appearing silently
Annual examinationThe cycle repeats, because buyers treat a report older than twelve months as stale

None of these is technically demanding. All of them fail the same way, which is quietly, when the person who was doing them becomes busy with something else.

How long does compliance last?

A report covers a stated past period. It does not expire on a fixed date, but its usefulness decays. Most buyers accept a report up to twelve months old and start asking questions beyond that.

Companies therefore run the examination annually, with each observation period beginning where the last one ended. Compliance in the everyday sense means being continuously inside that cycle, not having completed it once.

The awkward consequence is that the day your report is issued, the period it describes has already finished and the next one has already begun. Controls that stop the following month will appear in next year's report. Keeping the position true between examinations is what our continuous governance and assurance service is built for.

What SOC 2 compliance does not cover

Being SOC 2 compliant does not make you compliant with anything else, and it is worth being precise about this because buyers sometimes assume otherwise.

It does not satisfy GDPR or UK GDPR. The Privacy criterion overlaps with data protection obligations, but SOC 2 says nothing about your lawful basis for processing, data subject rights, or international transfers.

It does not satisfy HIPAA, PCI DSS or any sector regulation, though the underlying controls often serve several at once.

It does not address AI governance. If your product uses AI, buyers are increasingly asking questions about model oversight, training data and human review that the Trust Services Criteria do not reach. ISO/IEC 42001 is the standard written for that, and our ISO/IEC 42001 guides set it out.

And it does not, by itself, mean a company is secure. It means the controls it described operated as described. A thin scope produces a clean report and a lot of follow-up questions from buyers who read carefully.

What to do next

Establish which report your buyer needs and which systems they care about. Then get an honest view of your current position before committing to a timetable.

Our free readiness diagnostic gives a first picture, and our readiness and gap assessment produces a requirement-by-requirement view for a fixed fee.

References

FAQ

What does SOC 2 compliant mean?

That an independent accounting firm has examined your controls against the selected criteria and issued a report, normally without significant exceptions.

Is SOC 2 compliance mandatory?

Not by law. It is mandatory in practice for many suppliers because buyers require it contractually.

How long is SOC 2 compliance valid?

The report covers a past period and does not formally expire, but most buyers consider one older than twelve months out of date.

Does SOC 2 compliance cover GDPR?

No. There is overlap on security controls, but SOC 2 does not address lawful basis, data subject rights or international transfers.

Can a small company be SOC 2 compliant?

Yes. Scope scales with the organisation, and a small company with a narrow scope and Security only can complete an examination straightforwardly.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act, from first assessment to report, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.