Do I need SOC 2?
No law requires SOC 2, but many buyers do. Answer five questions about who you sell to and what they ask for, and see whether a SOC 2 report is worth doing now, which type to start with, and what to do first.
No law requires SOC 2. You need it when your customers require it: usually a B2B company that stores or processes customer data and sells to mid-size or enterprise buyers, especially in the United States. If prospects send security questionnaires or ask for your SOC 2 report, plan one: a Type 1 first if a deal is waiting, then a Type 2.
Result
Not by law, but in practice: when prospects ask for a SOC 2 report, deals stall or fall through without one. Start now. A Type 1 report can be ready in weeks if your controls are in place; a Type 2 follows after an observation period.
- Scope: list the systems that store or process customer data, and choose the Trust Services Criteria. Security is always in; add Availability or Confidentiality if customers rely on them.
- Readiness: close the usual gaps first: access reviews, MFA everywhere, device management, change management, vendor reviews, incident response. See the SOC 2 guide.
- Type: a Type 1 report can unblock a deal in weeks; most enterprise buyers then want a Type 2 covering 3 to 12 months.
What SOC 2 is
SOC 2 is an attestation report, issued by a licensed CPA firm under the AICPA's attestation standards, on how a service organisation's controls meet the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality and privacy. It is a report, not a certificate: there is no pass mark, and the auditor's opinion and any exceptions are in the report itself.
Why it is required without being a law
No statute requires SOC 2. Buyers require it, in procurement policies and contracts, because it lets them rely on an independent auditor instead of assessing every vendor themselves. That is why the honest answer to "do I need SOC 2" depends on who you sell to, not on where you are incorporated.
Type 1 or Type 2
A Type 1 report covers the design of controls at a point in time; a Type 2 covers how they operated over a period, usually 3 to 12 months. A Type 1 can unblock a deal quickly. Enterprise buyers usually expect a Type 2, renewed every year. See Type 1 vs Type 2.
Sources
- AICPA: SOC 2: SOC for Service Organizations: Trust Services Criteria
- AICPA: 2017 Trust Services Criteria (with revised points of focus, 2022)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Is SOC 2 a legal requirement?
No. No law requires a SOC 2 report. It becomes a requirement when a customer's procurement policy or contract demands it, which is common for US mid-market and enterprise buyers.
Who needs SOC 2?
Service organisations that store, process or transmit data for business customers: SaaS companies, cloud and hosting providers, managed service providers, data processors and payment or HR platforms selling to other businesses.
Does a startup need SOC 2?
Only when its buyers ask for it. Early-stage startups selling to small businesses rarely need one; a startup selling to enterprises usually needs one before its first large deal closes.
How long does SOC 2 take?
A Type 1 can be issued within weeks once controls are in place. A Type 2 needs an observation period, usually 3 to 12 months, plus the audit itself. Readiness work before either often takes 1 to 3 months.
Is SOC 2 or ISO 27001 better?
Neither is better; they answer different buyers. SOC 2 is expected in the United States, ISO 27001 in Europe and much of Asia. Most controls overlap, so many companies do one and then add the other.
Do I need SOC 2 if I use AWS, Azure or Google Cloud?
Yes, if your buyers ask. The cloud provider's own SOC 2 covers its infrastructure, not your application, access controls, change management or people. Your report can rely on theirs for the parts they run.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.