Screenata

SOC 2 Basics for Founders

Is SOC 2 legally required?

August 22, 20263 min read

Is SOC 2 legally required?

No. SOC 2 is not required by any law, regulation, or government agency. It is a voluntary attestation standard created by the AICPA (the American Institute of Certified Public Accountants), a private professional body, and no statute in the US or anywhere else references it as an obligation. Nobody gets fined for not having SOC 2. The pressure to get one comes entirely from customers, who write it into procurement requirements and vendor security reviews.

What SOC 2 actually is

A SOC 2 report is an independent CPA firm's attestation that your controls meet the AICPA Trust Services Criteria. It comes in two forms: Type I examines control design at a point in time, and Type II examines whether controls operated over a period, usually 3 to 12 months. It is an audit opinion, not a certification and not a license. There is no government registry of SOC 2 holders and no regulator that checks whether you have one.

SOC 2 versus regimes that are actually law

The confusion usually comes from lumping SOC 2 in with legal regimes it gets compared to. The table separates them.

RegimeLegally required?Who enforces itWho it applies to
SOC 2No, voluntary attestationCustomers, via contracts and procurementAny service organization whose customers ask
HIPAAYes, US federal lawHHS Office for Civil RightsHealthcare providers, plans, and their business associates
GDPRYes, EU regulationEU data protection authoritiesAnyone processing EU residents' personal data
NYDFS 23 NYCRR 500Yes, state regulationNew York Department of Financial ServicesNY-licensed banks, insurers, and financial firms
PCI DSSNo statute, but contractually requiredCard networks and acquiring banksAnyone handling card payments

Two things follow from this. First, if you are subject to HIPAA or GDPR, a SOC 2 report does not discharge those obligations; the laws impose their own requirements directly. Second, PCI DSS is the closest analogue to SOC 2: both are private-sector requirements enforced through contracts, and both are unavoidable in practice for the companies they touch.

Why it feels mandatory anyway

For B2B software companies, SOC 2 operates as a de facto requirement because it is the standard artifact security teams ask for. A typical enterprise security review asks for a SOC 2 Type II report before anything else, and "we do not have one" commonly stalls or kills the deal, or gets you routed into a longer questionnaire process instead. The requirement is real; its source is the contract in front of you rather than a statute.

That distinction matters for timing. A legal requirement applies from day one. A commercial requirement applies when your pipeline says so, which means an early-stage company selling to startups can reasonably defer SOC 2, and a company entering mid-market sales cycles usually cannot. Most teams start the process when the first serious deal asks for it, and a Type II report takes an observation window of 3 to 12 months plus audit time, so starting after the deal arrives means months of delay.

What it costs to close the gap

Because the requirement is commercial, the decision is a deal-economics calculation rather than a legal one: the cost of the report against the revenue it unblocks. A SOC 2 Type I package from Screenata is $299 one-time, and a full program runs $5,988/year per framework ($499/mo) for teams under 50 employees, with about 70% of evidence collected automatically. Audit fees from the CPA firm are separate, since Screenata is not an auditor and the attestation must come from an independent CPA. See pricing for what each tier covers.

The short version

No law requires SOC 2. Your next enterprise contract probably will.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.