Free tool · SOC 2

Do I need SOC 2?

No law requires SOC 2, but many buyers do. Answer five questions about who you sell to and what they ask for, and see whether a SOC 2 report is worth doing now, which type to start with, and what to do first.

Short answer

No law requires SOC 2. You need it when your customers require it: usually a B2B company that stores or processes customer data and sells to mid-size or enterprise buyers, especially in the United States. If prospects send security questionnaires or ask for your SOC 2 report, plan one: a Type 1 first if a deal is waiting, then a Type 2.

Answer for your organisation

SOC 2 reports on a service organisation's controls over the data it handles for its customers.
SOC 2 is a US standard. Outside the US, buyers often ask for ISO 27001 instead or as well.
Worked example: a US B2B SaaS company selling to enterprises

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Required: your buyers are asking for it

Not by law, but in practice: when prospects ask for a SOC 2 report, deals stall or fall through without one. Start now. A Type 1 report can be ready in weeks if your controls are in place; a Type 2 follows after an observation period.

Security (the common criteria), always in scopeTSC CC1–CC9
Availability, Confidentiality, Processing Integrity, Privacy: add those customers rely onTSC A, C, PI, P
Report by a licensed CPA firmAICPA AT-C 205
  • Scope: list the systems that store or process customer data, and choose the Trust Services Criteria. Security is always in; add Availability or Confidentiality if customers rely on them.
  • Readiness: close the usual gaps first: access reviews, MFA everywhere, device management, change management, vendor reviews, incident response. See the SOC 2 guide.
  • Type: a Type 1 report can unblock a deal in weeks; most enterprise buyers then want a Type 2 covering 3 to 12 months.
01

What SOC 2 is

SOC 2 is an attestation report, issued by a licensed CPA firm under the AICPA's attestation standards, on how a service organisation's controls meet the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality and privacy. It is a report, not a certificate: there is no pass mark, and the auditor's opinion and any exceptions are in the report itself.

02

Why it is required without being a law

No statute requires SOC 2. Buyers require it, in procurement policies and contracts, because it lets them rely on an independent auditor instead of assessing every vendor themselves. That is why the honest answer to "do I need SOC 2" depends on who you sell to, not on where you are incorporated.

03

Type 1 or Type 2

A Type 1 report covers the design of controls at a point in time; a Type 2 covers how they operated over a period, usually 3 to 12 months. A Type 1 can unblock a deal quickly. Enterprise buyers usually expect a Type 2, renewed every year. See Type 1 vs Type 2.

04

Sources

Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.

Questions

The things people ask us

Is SOC 2 a legal requirement?

No. No law requires a SOC 2 report. It becomes a requirement when a customer's procurement policy or contract demands it, which is common for US mid-market and enterprise buyers.

Who needs SOC 2?

Service organisations that store, process or transmit data for business customers: SaaS companies, cloud and hosting providers, managed service providers, data processors and payment or HR platforms selling to other businesses.

Does a startup need SOC 2?

Only when its buyers ask for it. Early-stage startups selling to small businesses rarely need one; a startup selling to enterprises usually needs one before its first large deal closes.

How long does SOC 2 take?

A Type 1 can be issued within weeks once controls are in place. A Type 2 needs an observation period, usually 3 to 12 months, plus the audit itself. Readiness work before either often takes 1 to 3 months.

Is SOC 2 or ISO 27001 better?

Neither is better; they answer different buyers. SOC 2 is expected in the United States, ISO 27001 in Europe and much of Asia. Most controls overlap, so many companies do one and then add the other.

Do I need SOC 2 if I use AWS, Azure or Google Cloud?

Yes, if your buyers ask. The cloud provider's own SOC 2 covers its infrastructure, not your application, access controls, change management or people. Your report can rely on theirs for the parts they run.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.