FAQ

SOC 2 frequently asked questions

Straight answers to the questions buyers ask before their first audit.

What is SOC 2?

SOC 2 is an auditing framework from the AICPA for service organizations. An independent CPA firm evaluates your controls against the Trust Services Criteria and issues a report your customers can rely on.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 assesses whether controls are suitably designed at a single point in time. Type 2 assesses design and whether controls operated effectively over a period (typically 6–12 months). Enterprise customers overwhelmingly ask for Type 2.

What are the Trust Services Criteria?

Five categories: Security (required), Availability, Processing Integrity, Confidentiality, and Privacy (optional). You and your auditor agree which apply to your system.

Who can perform a SOC 2 audit?

Only a licensed CPA firm, under AICPA attestation standards. Compliance automation platforms prepare evidence but cannot sign reports.

How much does a SOC 2 audit cost?

Published audit-fee ranges run $7,000–$100,000 for Type 2; first-year all-in costs (readiness, tooling, staff time) typically $30,000–$150,000. See the cost guide.

How long does it take?

Nine to fifteen months end to end for a first Type 2, including a 3–12 month observation period. Details on the timeline page.

Still have questions? Auditors answer scoping questions free as part of quoting — tell us your scope once and matched firms respond.

Ask auditors directly
Is SOC 2 a certification?

Strictly speaking, no — it's an attestation report, not a certification with a certificate number. In practice, buyers treat it like one: 'SOC 2 certified' in sales decks means 'we hold a clean SOC 2 Type 2 report.'

Do startups need SOC 2?

If you sell to mid-market or enterprise customers — especially in SaaS, fintech, or healthcare — expect it in security reviews. Many startups pursue it at Seed/Series A when deals start stalling on security questionnaires.

What happens if the auditor finds issues?

Findings become 'exceptions' or 'qualifications' in the report — there is no pass/fail. You can remediate and note it in management's response; serious unremediated issues make the report harder to sell to customers, which is why readiness work matters.

How often must SOC 2 be renewed?

Reports cover a defined period (usually 12 months), so most companies re-audit annually to keep a current report for customers. Year-two costs typically drop 30–50%.

Can one auditor do SOC 2 and ISO 27001 together?

Yes — many firms (A-LIGN, Schellman, BARR Advisory, Sensiba) offer both, and combined audits can share evidence and reduce total cost.

How do I choose a SOC 2 auditor?

Verify the firm is a licensed CPA practice and confirm which entity signs your report. Ask who the engagement team is, whether the fee is fixed and what breaks it, how added Trust Services Criteria are priced, and whether you can speak to two reference clients your size. Our nine-question checklist covers it.

Can I switch SOC 2 auditors?

Yes. You can change firms between audit cycles with no penalty beyond a new engagement letter — and you can switch mid-engagement, though expect evidence handoff friction and possible re-testing. Our switching guide walks through timing, costs, and the questions to ask the new firm.

Do compliance platforms replace the auditor?

No. Only a licensed CPA firm can sign the SOC 2 report. Platforms (Vanta, Drata, Secureframe) collect evidence; readiness firms prepare you; the auditor issues the opinion. See who does what.

What is AICPA peer review, and do you check it?

Peer review is an independent check of a CPA firm's audit practice under an AICPA program — a useful diligence signal, not a quality guarantee. We do not claim to verify peer-review records: our methodology explains exactly what we check, and links the public AICPA lookup so you can check any firm yourself in minutes.

Can I combine SOC 2 and ISO 27001 into one audit?

Yes — many firms perform both, and a combined engagement can share evidence across the two frameworks instead of running two separate audits. See our combined-audit guide for sequencing, cost framing, and pitfalls.

Still have questions?

Get matched with auditors who answer scoping questions free — it's part of how they win business.

Get a free quote