SOC 2 Basics for Founders
What is SOC 2 certification?
What is SOC 2 certification?
There is no SOC 2 certification. SOC 2 produces an attestation report: a licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report containing its opinion. There is no certificate, no certifying body, and no badge. The term "SOC 2 certified" is used constantly and it is not accurate, which matters more than it sounds.
Certification and attestation are different things
| Certification (ISO 27001) | Attestation (SOC 2) | |
|---|---|---|
| Issued by | An accredited certification body | A licensed CPA firm |
| Output | A certificate | A report with an opinion |
| Shared how | Displayed publicly | Under NDA, on request |
| Time model | Valid for three years with surveillance | Covers a defined period |
| Verified by | Accreditation bodies | AICPA peer review |
Why the distinction has practical consequences
You cannot display it. There is no badge to put in your footer that means anything. What you have is a document, usually shared under NDA during a security review. Vendors selling "SOC 2 certified" seals are selling something the framework does not produce.
It covers a period, not a date. A Type II report covers an observation window. When that window ends, coverage does not extend to today, which is why bridge letters exist.
Only a CPA firm can issue it. Platforms and consultants prepare you. They cannot sign the opinion, and independence rules prevent whoever produced the evidence from attesting to it. Any vendor implying otherwise is describing something that would not be a SOC 2 report.
Type I and Type II
- Type I tests whether controls are suitably designed at a point in time. Faster and cheaper, and commonly accepted while you work toward Type II.
- Type II tests whether they operated effectively throughout a period, typically three to twelve months. This is what most enterprise buyers eventually want, because it tests operation rather than intent.
What buyers actually ask for
In practice a security review asks for the report itself, and increasingly for a current one. Saying "we are SOC 2 certified" to a procurement team that knows the difference reads as unfamiliarity with your own compliance posture. Saying "we have a SOC 2 Type II report covering January to December, and I can share it under NDA" reads as competence.
What it costs
Audit fees for a small company commonly run $10,000 to $60,000 depending on scope and firm, paid to the auditor. Preparation is separate. See what does a SOC 2 audit actually cost.