Screenata

SOC 2 Basics for Founders

What is SOC 2 certification?

August 18, 20262 min read

What is SOC 2 certification?

There is no SOC 2 certification. SOC 2 produces an attestation report: a licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report containing its opinion. There is no certificate, no certifying body, and no badge. The term "SOC 2 certified" is used constantly and it is not accurate, which matters more than it sounds.

Certification and attestation are different things

Certification (ISO 27001)Attestation (SOC 2)
Issued byAn accredited certification bodyA licensed CPA firm
OutputA certificateA report with an opinion
Shared howDisplayed publiclyUnder NDA, on request
Time modelValid for three years with surveillanceCovers a defined period
Verified byAccreditation bodiesAICPA peer review

Why the distinction has practical consequences

You cannot display it. There is no badge to put in your footer that means anything. What you have is a document, usually shared under NDA during a security review. Vendors selling "SOC 2 certified" seals are selling something the framework does not produce.

It covers a period, not a date. A Type II report covers an observation window. When that window ends, coverage does not extend to today, which is why bridge letters exist.

Only a CPA firm can issue it. Platforms and consultants prepare you. They cannot sign the opinion, and independence rules prevent whoever produced the evidence from attesting to it. Any vendor implying otherwise is describing something that would not be a SOC 2 report.

Type I and Type II

  • Type I tests whether controls are suitably designed at a point in time. Faster and cheaper, and commonly accepted while you work toward Type II.
  • Type II tests whether they operated effectively throughout a period, typically three to twelve months. This is what most enterprise buyers eventually want, because it tests operation rather than intent.

What buyers actually ask for

In practice a security review asks for the report itself, and increasingly for a current one. Saying "we are SOC 2 certified" to a procurement team that knows the difference reads as unfamiliarity with your own compliance posture. Saying "we have a SOC 2 Type II report covering January to December, and I can share it under NDA" reads as competence.

What it costs

Audit fees for a small company commonly run $10,000 to $60,000 depending on scope and firm, paid to the auditor. Preparation is separate. See what does a SOC 2 audit actually cost.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.