Skip to main content
All articles

Audit Readiness

What Is SOC 2? Reports, Scope, and Readiness Explained

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

What Is SOC 2? Reports, Scope, and Readiness Explained: original RiskSensai editorial cover

What a SOC 2 report tells a reader

SOC 2 is part of the AICPA's System and Organization Controls suite of CPA services.1 It concerns a service organization's controls within an agreed system and reporting scope. It is often requested when one business relies on another to host, process or protect important information.

The useful question is not whether a company has a badge on its website. It is whether a relevant report gives the intended reader information about the service, commitments, controls, period and results they need to evaluate.

Calling SOC 2 a “certification” can obscure that distinction. The output is a professional report, not a universal approval of every product, location, legal obligation or future activity of the organization.

Understand the trust-services categories

The AICPA's current resource listing identifies criteria concerning security, availability, processing integrity, confidentiality and privacy.2 Confirm the applicable categories and criteria with the CPA firm for your actual engagement.

In plain language, those topics concern protecting systems and information, making services available for their commitments, processing correctly, protecting confidential information and handling personal information appropriately. They overlap, but they are not interchangeable.

Do not add categories because the names sound impressive. Start with the service commitments and the intended users' needs. A firm promising specific processing results faces different questions from one merely storing files. A confidentiality commitment is not automatically a complete privacy program.

Type 1 and Type 2 address different questions

The AICPA's publicly available historical criteria edition explains that Type 2 includes an opinion on operating effectiveness and tests of controls, while Type 1 does not.3 Current engagement details must follow the applicable professional standards and current guidance.

QuestionType 1Type 2
TimingA specified dateA specified period
Main distinctionDescription and suitability of control designAlso addresses operation across the period
Evidence planningSupport the state at the relevant dateRetain evidence for relevant occurrences through the period
Buyer discussionAsk whether a point-in-time report meets the needAsk which period, service and categories the buyer needs

A Type 1 report is not evidence that controls operated consistently for a later year. A Type 2 report is not a prediction that they will operate without exception forever. The dates and scope remain essential when a customer evaluates either.

Avoid promises of an instant Type 2 report. The operating period and the professional examination cannot be replaced by buying software or uploading policies. Agree the period and examination approach with the firm before planning a delivery date.

Define the service and system boundary

Write down what service the report is intended to cover. Include the relevant people, processes, technology, data and providers. Identify how the service is delivered and which customer commitments matter.

Consider a fictional company with a hosted analytics product and a separate consulting service. A report scoped to the hosted product should not be described as independently assessing every consulting engagement. Similarly, a report for one regional environment may not cover a new environment launched later.

Before engaging the CPA firm, ask:

  1. Which service and deployment environments are included?
  2. Which legal entities, locations and operating teams are relevant?
  3. Which categories and criteria are proposed, and why?
  4. How are important outsourced providers represented?
  5. What responsibilities remain with customers using the service?
  6. What date or period is proposed?
  7. Who are the intended report users, and how will sharing be handled?

These questions produce a useful scope discussion. They do not establish the answer independently of the engagement.

Readiness is management preparation

Readiness work helps management identify gaps, assign owners and gather evidence before the examination. It might include clarifying service commitments, documenting controls, testing recovery assumptions and correcting access-management gaps.

A self-assessment result, readiness checklist or consultant's recommendations should be labeled as that kind of output. They do not become a SOC 2 report because they use similar terminology or map to the criteria.

Make three separate records: what the control is designed to do, whether it has been implemented, and what evidence shows it operated. This prevents a policy approval from being counted as months of operational evidence.

Worked example: customer-access removal

This fictional example illustrates preparation for a scoped control discussion. A hosted software company removes support access when an employee leaves. The policy says removals are required, but the team has no consistent completion record.

Preparation questionUseful record
Who starts the process?Departure trigger and HR responsibility
Which systems are covered?Staff-access inventory linked to the service
Who performs removal?Named technical owner and backup
How is completion checked?Ticket showing systems and removal times
What happens when removal is late?Exception, impact assessment and corrective action

The team tests a synthetic departure and discovers a secondary support tool was missed. It updates the inventory and process, then retains subsequent real operational records under appropriate access controls. The failed test is useful evidence of a gap and its response; deleting it would make the history less trustworthy.

The CPA firm's examination requirements and sample selection remain separate. Management should not preselect only successful records and treat them as a complete population.

Questions to ask a prospective CPA firm

Ask about licensing, relevant service experience, professional standards, quality oversight, independence and the specific scope of the quote. Clarify what management must provide, how findings are discussed and what the expected report includes.

Separate readiness consulting from the examination, including who performs each and how independence is maintained. Clarify the treatment of scope changes, delayed evidence and a changed operating period. Use the SOC 2 budget worksheet to separate the examination fee from preparation and ongoing work. A sales promise should not replace the written engagement terms.

If a vendor advertises a guaranteed “clean” report or a very fast completion regardless of evidence, ask how the professional work is performed. The current AICPA resource page specifically cautions users to evaluate SOC services carefully.1

How to read a supplier's report

First confirm the named organization, system and date or period. Compare them with the service your business actually uses. Read the opinion, system description, exceptions and relevant customer responsibilities; do not stop at the cover page.

Ask how changes after the period are addressed. A supplier letter about later changes is a different kind of evidence from the examiner's report. Note any service components outside the report boundary and decide whether further due diligence is needed.

Handle the report according to its permitted distribution and your own information-access rules. A detailed report may contain sensitive operational information; public marketing should not reproduce it casually.

A practical next step

Document the customer need, service boundary and proposed report type before collecting dozens of policies. Then speak with an appropriate CPA firm and build a readiness plan around the agreed scope. That sequence helps avoid unnecessary work and unsupported promises while giving customers a clearer explanation of what the eventual report will address.

Sources and references

  1. AICPA & CIMA. System and Organization Controls: SOC Suite of Services. Identifies the CPA SOC reporting services and directs readers to the applicable professional resources. ↩ ↩2

  2. AICPA & CIMA. 2017 Trust Services Criteria (With Revised Points of Focus - 2022) (2023-09-30). Current resource listing identifies the trust-services criteria; downloading the complete resource requires a free account. ↩

  3. AICPA. 2017 Trust Services Criteria, including March 2020 updates (2020-03). Public historical edition explains Type 1/Type 2 and readiness versus examination. Use the current 2022 revised-points-of-focus resource for an engagement. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • SOC 2
  • Audit Readiness
  • Evidence
Connecting to your conversation workspace…