Cibernetica.io

Compliance

SOC 2

Get the controls in place, then evidence them over time.

SOC 2 is the report US enterprise buyers most commonly ask for. It is not a certification and there is no certificate — it is an examination performed by a licensed CPA firm, resulting in a report describing your controls and the auditor's opinion on them. Understanding that difference matters, because it changes what you are buying and who you buy it from.

Type 1, Type 2, and why the timeline works the way it does

SOC 2 is built on five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is always in scope. The others are included only if relevant to what you do and what your customers care about — including all five when only security is needed adds cost for no commercial return. A Type 1 report assesses whether controls are suitably designed at a single point in time. A Type 2 report assesses whether they operated effectively across an observation period, typically three to twelve months. Type 2 is what most enterprise buyers actually want. That observation period is the part that surprises people. You cannot compress it. Controls must be running, and generating evidence, for the full window before the auditor can opine on them. A company that needs a Type 2 report for a deal closing in two months cannot get one, regardless of budget. The examination must be performed by a licensed CPA firm. Readiness consultants prepare you; they cannot issue the report. These are necessarily two separate engagements with two separate parties.

Who needs it

  • Software and service companies selling to US enterprise customers
  • Businesses where a deal is blocked pending a security review
  • Companies whose customers process personal or financial data through their platform
  • Organisations already holding ISO 27001 and now facing US buyers who want SOC 2 specifically

What you get

Realistic timeline planning

The observation period sets a floor on how quickly a Type 2 report can exist. Planning backward from that avoids committing to a customer date you cannot meet.

Scoping the criteria

Which Trust Services Criteria genuinely belong in scope, so you are not paying to be audited against things nobody asked about.

Readiness before the auditor arrives

Control design, evidence collection, and gap remediation, so the examination itself is a confirmation rather than a discovery exercise.

Frequently asked questions

What is the difference between Type 1 and Type 2?

Type 1 assesses whether your controls are suitably designed at a specific date. Type 2 assesses whether they actually operated effectively over a period, usually three to twelve months. Type 2 carries considerably more weight with buyers. Companies under time pressure sometimes obtain a Type 1 first to unblock a deal, then complete Type 2 in the following cycle.

How long does SOC 2 take?

Readiness work commonly runs two to four months, followed by the observation period, followed by the examination and report issuance. For a Type 2 starting from nothing, six to nine months end to end is a realistic expectation. The observation period is fixed and cannot be shortened by spending more.

How much does it cost?

Two distinct costs: readiness consultancy, and the CPA firm's audit fee. Both scale with scope — the number of criteria in scope, the complexity of your systems, and how much evidence collection is automated versus manual. Compliance automation tooling adds a third cost but often reduces the first, particularly for evidence gathering.

We have ISO 27001 already. Do we need SOC 2 as well?

If your US customers are asking for SOC 2 specifically, then generally yes — the two are not interchangeable in procurement even though the underlying controls overlap substantially. The good news is that overlap: an organisation with a functioning ISMS has most of what a SOC 2 examination looks for, and the incremental work is mapping and evidencing rather than rebuilding.