<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is SOC 2 certification?"
title: "What Is SOC 2 Certification"
seoTitle: "SOC 2 Certification: Why It Is Not a Certification"
summary: "There is no such thing as SOC 2 certification. SOC 2 produces an attestation report containing a licensed CPA firm's opinion on whether your controls meet the Trust Services Criteria, not a certificate. The distinction is practical: you share a report under NDA rather than displaying a badge, the report covers a defined period rather than expiring, and only a CPA firm can issue it."
publishedAt: "2026-08-18"
keywords:
  - "SOC 2 certification"
  - "soc2 certification"
  - "SOC 2 certified"
  - "is SOC 2 a certification"
pillar: "SOC 2 Basics for Founders"
faqs:
  - question: "Is SOC 2 a certification?"
    answer: "No. SOC 2 is an attestation. A licensed CPA firm examines your controls and issues a report containing its opinion. There is no certificate and no certifying body, which is why you share a report rather than displaying a badge, and why nobody can be 'SOC 2 certified' in the way they can be ISO 27001 certified."
  - question: "How long is a SOC 2 report valid?"
    answer: "A report does not expire, it covers a period. A Type II report covers an observation window, commonly three to twelve months. Once that window ends, buyers begin asking for a bridge letter, and beyond a few months they expect a current report. Most companies run an annual cycle."
  - question: "Who can issue a SOC 2 report?"
    answer: "Only a licensed CPA firm, under AICPA standards. Consultants and compliance platforms can prepare you, but cannot issue the opinion. Independence rules also prevent the party that produced your evidence from attesting to it."
---

## What is SOC 2 certification?

**There is no SOC 2 certification.** SOC 2 produces an **attestation report**: a licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report containing its opinion. There is no certificate, no certifying body, and no badge. The term "SOC 2 certified" is used constantly and it is not accurate, which matters more than it sounds.

### Certification and attestation are different things

| | Certification (ISO 27001) | Attestation (SOC 2) |
|---|---|---|
| Issued by | An accredited certification body | A licensed CPA firm |
| Output | A certificate | A report with an opinion |
| Shared how | Displayed publicly | Under NDA, on request |
| Time model | Valid for three years with surveillance | Covers a defined period |
| Verified by | Accreditation bodies | AICPA peer review |

## Why the distinction has practical consequences

**You cannot display it.** There is no badge to put in your footer that means anything. What you have is a document, usually shared under NDA during a security review. Vendors selling "SOC 2 certified" seals are selling something the framework does not produce.

**It covers a period, not a date.** A Type II report covers an observation window. When that window ends, coverage does not extend to today, which is why [bridge letters](/resources/answers/what-is-a-soc-2-bridge-letter-and-when-do-you-need-one) exist.

**Only a CPA firm can issue it.** Platforms and consultants prepare you. They cannot sign the opinion, and independence rules prevent whoever produced the evidence from attesting to it. Any vendor implying otherwise is describing something that would not be a SOC 2 report.

## Type I and Type II

- **Type I** tests whether controls are suitably designed at a point in time. Faster and cheaper, and commonly accepted while you work toward Type II.
- **Type II** tests whether they **operated effectively throughout a period**, typically three to twelve months. This is what most enterprise buyers eventually want, because it tests operation rather than intent.

## What buyers actually ask for

In practice a security review asks for the report itself, and increasingly for a current one. Saying "we are SOC 2 certified" to a procurement team that knows the difference reads as unfamiliarity with your own compliance posture. Saying "we have a SOC 2 Type II report covering January to December, and I can share it under NDA" reads as competence.

## What it costs

Audit fees for a small company commonly run $10,000 to $60,000 depending on scope and firm, paid to the auditor. Preparation is separate. See [what does a SOC 2 audit actually cost](/resources/answers/what-does-a-soc-2-audit-actually-cost).
