FAQ

SOC 2 frequently asked questions

Straight answers to the questions buyers ask before their first audit.

What is SOC 2?

SOC 2 is an auditing framework from the AICPA for service organizations. An independent CPA firm evaluates your controls against the Trust Services Criteria and issues a report your customers can rely on.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 assesses whether controls are suitably designed at a single point in time. Type 2 assesses design and whether controls operated effectively over a period (typically 6–12 months). Enterprise customers overwhelmingly ask for Type 2.

What are the Trust Services Criteria?

Five categories: Security (required), Availability, Processing Integrity, Confidentiality, and Privacy (optional). You and your auditor agree which apply to your system.

Who can perform a SOC 2 audit?

Only a licensed CPA firm, under AICPA attestation standards. Compliance automation platforms prepare evidence but cannot sign reports.

How much does a SOC 2 audit cost?

Published audit-fee ranges run $7,000–$100,000 for Type 2; first-year all-in costs (readiness, tooling, staff time) typically $30,000–$150,000. See the cost guide.

How long does it take?

Nine to fifteen months end to end for a first Type 2, including a 3–12 month observation period. Details on the timeline page.

Is SOC 2 a certification?

Strictly speaking, no — it's an attestation report, not a certification with a certificate number. In practice, buyers treat it like one: 'SOC 2 certified' in sales decks means 'we hold a clean SOC 2 Type 2 report.'

Do startups need SOC 2?

If you sell to mid-market or enterprise customers — especially in SaaS, fintech, or healthcare — expect it in security reviews. Many startups pursue it at Seed/Series A when deals start stalling on security questionnaires.

What happens if the auditor finds issues?

Findings become 'exceptions' or 'qualifications' in the report — there is no pass/fail. You can remediate and note it in management's response; serious unremediated issues make the report harder to sell to customers, which is why readiness work matters.

How often must SOC 2 be renewed?

Reports cover a defined period (usually 12 months), so most companies re-audit annually to keep a current report for customers. Year-two costs typically drop 30–50%.

Can one auditor do SOC 2 and ISO 27001 together?

Yes — many firms (A-LIGN, Schellman, BARR Advisory, Sensiba) offer both, and combined audits can share evidence and reduce total cost.

How do I choose a SOC 2 auditor?

Verify the CPA license, ask who your engagement team will be, confirm fixed vs hourly fees and scope boundaries, and check experience with your stack. Our nine-question checklist covers it.

Can I switch SOC 2 auditors?

Yes. You can change firms between audit cycles with no penalty beyond a new engagement letter — and you can switch mid-engagement, though expect evidence handoff friction and possible re-testing. Our switching guide walks through timing, costs, and the questions to ask the new firm.

Do compliance platforms replace the auditor?

No. Only a licensed CPA firm can sign the SOC 2 report. Platforms (Vanta, Drata, Secureframe) collect evidence; readiness firms prepare you; the auditor issues the opinion. See who does what.

What is AICPA peer review, and do you check it?

Peer review is an independent check of a CPA firm's audit practice under an AICPA program — a useful diligence signal, not a quality guarantee. We do not claim to verify peer-review records: our methodology explains exactly what we check, and links the public AICPA lookup so you can check any firm yourself in minutes.

Can I combine SOC 2 and ISO 27001 into one audit?

Yes — many firms perform both, and a combined engagement can share evidence across the two frameworks instead of running two separate audits. See our combined-audit guide for sequencing, cost framing, and pitfalls.

Still have questions?

Get matched with auditors who answer scoping questions free — it's part of how they win business.

Get a free quote