<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "Is SOC 2 legally required?"
title: "Is SOC 2 Legally Required"
seoTitle: "SOC 2 Legal Requirements"
summary: "No. SOC 2 is not required by any law or regulator in any country. It is a voluntary attestation framework defined by the AICPA, a private professional body, and no statute references it. The requirement is commercial: enterprise customers demand a SOC 2 report during procurement and security review, and many will not sign without one. That makes SOC 2 effectively mandatory for B2B software companies selling upmarket, even though the obligation comes from contracts rather than statutes. This is different from HIPAA, GDPR, or the NYDFS cybersecurity regulation, which are actual legal regimes with regulators and penalties behind them."
publishedAt: "2026-08-22"
keywords:
  - "is SOC 2 legally required"
  - "is SOC 2 mandatory"
  - "SOC 2 law"
  - "SOC 2 compliance requirement"
pillar: "SOC 2 Basics for Founders"
faqs:
  - question: "is soc 2 mandatory?"
    answer: "Not legally. No law, regulator, or government agency requires SOC 2. It becomes mandatory in practice when your customers require it in contracts or security reviews, which is common once you sell to mid-market and enterprise buyers. The obligation is commercial, and it is enforced by lost deals rather than fines."
  - question: "what law requires soc 2?"
    answer: "None. SOC 2 is defined by the AICPA, the US professional body for accountants, and no statute or regulation references it as a requirement. Laws like HIPAA and GDPR impose their own security obligations directly. A SOC 2 report can serve as evidence of security practices under those regimes, but it does not satisfy them by itself."
  - question: "can you sell software without soc 2?"
    answer: "Yes, and most early-stage companies do. Selling to individuals, small businesses, and startups rarely requires it. The wall appears when a buyer's procurement or security team asks for a SOC 2 report as a condition of signing, which typically starts with mid-market deals. At that point the report is the cost of entry to the deal, whatever the law says."
  - question: "who is required to have a soc 2 report?"
    answer: "By law, nobody. In practice, service organizations that handle customer data and sell to enterprises are the ones asked for it: SaaS companies, hosting and infrastructure providers, payroll and HR platforms, and managed service providers. The requirement arrives through a customer's procurement or vendor security review, so who needs SOC 2 is determined by who your buyers are rather than by what your company does."
  - question: "what happens if you fail a soc 2 audit?"
    answer: "There is no pass or fail. The auditor issues an opinion on your controls and lists any exceptions found during testing, and the report is delivered either way. A qualified opinion or a long list of exceptions is what buyers react to, since it signals controls that did not operate as described. The normal response is to remediate the gaps and go through a new attestation period with cleaner results."
  - question: "do you need a cpa to get soc 2?"
    answer: "The attestation itself must come from a licensed CPA firm; only a CPA firm can issue a SOC 2 report under the AICPA's standards. The preparation work does not require one: defining controls, writing policies, and collecting evidence can be done by your own team or with software. Most companies split it exactly that way, preparing internally and hiring the CPA firm only for the audit."
---

## Is SOC 2 legally required?

No. SOC 2 is not required by any law, regulation, or government agency. It is a voluntary attestation standard created by the AICPA (the American Institute of Certified Public Accountants), a private professional body, and no statute in the US or anywhere else references it as an obligation. Nobody gets fined for not having SOC 2. The pressure to get one comes entirely from customers, who write it into procurement requirements and vendor security reviews.

## What SOC 2 actually is

A SOC 2 report is an independent CPA firm's attestation that your controls meet the AICPA Trust Services Criteria. It comes in two forms: Type I examines control design at a point in time, and Type II examines whether controls operated over a period, usually 3 to 12 months. It is an audit opinion, not a certification and not a license. There is no government registry of SOC 2 holders and no regulator that checks whether you have one.

## SOC 2 versus regimes that are actually law

The confusion usually comes from lumping SOC 2 in with legal regimes it gets compared to. The table separates them.

| Regime | Legally required? | Who enforces it | Who it applies to |
|---|---|---|---|
| SOC 2 | No, voluntary attestation | Customers, via contracts and procurement | Any service organization whose customers ask |
| HIPAA | Yes, US federal law | HHS Office for Civil Rights | Healthcare providers, plans, and their business associates |
| GDPR | Yes, EU regulation | EU data protection authorities | Anyone processing EU residents' personal data |
| NYDFS 23 NYCRR 500 | Yes, state regulation | New York Department of Financial Services | NY-licensed banks, insurers, and financial firms |
| PCI DSS | No statute, but contractually required | Card networks and acquiring banks | Anyone handling card payments |

Two things follow from this. First, if you are subject to HIPAA or GDPR, a SOC 2 report does not discharge those obligations; the laws impose their own requirements directly. Second, PCI DSS is the closest analogue to SOC 2: both are private-sector requirements enforced through contracts, and both are unavoidable in practice for the companies they touch.

## Why it feels mandatory anyway

For B2B software companies, SOC 2 operates as a de facto requirement because it is the standard artifact security teams ask for. A typical enterprise security review asks for a SOC 2 Type II report before anything else, and "we do not have one" commonly stalls or kills the deal, or gets you routed into a longer questionnaire process instead. The requirement is real; its source is the contract in front of you rather than a statute.

That distinction matters for timing. A legal requirement applies from day one. A commercial requirement applies when your pipeline says so, which means an early-stage company selling to startups can reasonably defer SOC 2, and a company entering mid-market sales cycles usually cannot. Most teams start the process when the first serious deal asks for it, and a Type II report takes an observation window of 3 to 12 months plus audit time, so starting after the deal arrives means months of delay.

## What it costs to close the gap

Because the requirement is commercial, the decision is a deal-economics calculation rather than a legal one: the cost of the report against the revenue it unblocks. A SOC 2 Type I package from Screenata is $299 one-time, and a full program runs $5,988/year per framework ($499/mo) for teams under 50 employees, with about 70% of evidence collected automatically. Audit fees from the CPA firm are separate, since Screenata is not an auditor and the attestation must come from an independent CPA. See [pricing](/pricing) for what each tier covers.

## The short version

No law requires SOC 2. Your next enterprise contract probably will.
