GetSOC2

What is SOC 2 and who actually needs one

SOC 2 is a report, not a certificate. Understanding what the document actually asserts is the difference between buying the right engagement and spending a year on the wrong one.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

SOC 2 is an attestation report on a service organization's controls, produced by an independent licensed CPA firm under the attestation standards of the American Institute of Certified Public Accountants. The report says what controls you claim to operate, what the CPA firm did to check them, and what opinion the firm reached. It is a document you hand to a customer who has asked how you protect their data.

Everything else on this page follows from the fact that SOC 2 produces a report rather than a pass mark.

5 Trust Services Criteria categories, only one of them mandatory

3 to 12 Months in a typical Type 2 observation window

0 Certificates issued, because SOC 2 is not a certification

What SOC 2 actually is

Three things have to be true at once for a document to be a SOC 2 report.

First, it is an attestation engagement. Management makes a written assertion about its own system and controls, and an independent practitioner examines that assertion and reports on whether it is fairly stated. The subject matter belongs to you and the opinion belongs to the CPA firm, which is why a SOC 2 report opens with your words and not the auditor's.

Second, it is performed by a licensed CPA firm. Not a security consultancy, not a platform vendor, not an internal team. The AICPA reserves this work to firms holding a CPA licence and subject to peer review, the same professional regime that governs financial statement audits.

Third, the controls are measured against the Trust Services Criteria, the AICPA's published set of criteria for security, availability, processing integrity, confidentiality and privacy. The criteria are fixed. The controls you use to meet them are yours to choose, which is why two companies with very different architectures can both hold a clean report. The SOC 2 requirements page works through what that choice looks like control by control.

Nobody is SOC 2 certified

The phrase appears on sales decks and vendor questionnaires every day, and it is wrong in a way that matters commercially. A certification is issued by an accredited body against a standard with defined requirements, and it produces a certificate with a registration number a third party can look up. ISO 27001 works that way. SOC 2 does not: no accreditation scheme, no registry, no certificate, no number, no logo. What exists is a report, dated, addressed to management, and normally released under a non-disclosure agreement.

Three consequences follow. You send a customer the report under NDA rather than a certificate. A report is not pass or fail: it can contain exceptions and still be a real report, and the opinion paragraph is the only way to know what you hold. And it covers a stated scope and period, saying nothing outside that. If your website claims "SOC 2 certified", the reader most likely to notice is the security analyst at the customer you are trying to close.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The five Trust Services Criteria

An examination covers one or more of five categories. Every SOC 2 report includes Security. The other four are optional.

The five Trust Services Criteria categories
CategoryWhat it addressesWhen to include it
Security (the common criteria)Protection of the system against unauthorised access, use, disclosure and damageAlways. It is mandatory in every report.
AvailabilityThe system is available for operation and use as committedYou have contractual uptime commitments a customer cares about
ConfidentialityInformation designated confidential is protected as committedYou hold customer data classified as confidential under contract
Processing integrityProcessing is complete, valid, accurate, timely and authorisedYou transform or calculate data where the output itself is the product
PrivacyPersonal information is collected, used, retained and disposed of as committedRarely, and usually only when a buyer has named it in writing

Almost every Canadian company scoping a first report takes Security only, for two reasons. Security is where the buyer's question actually lives, since a vendor review asks about access control, change management, monitoring and incident response, and all of that sits in the common criteria. And every added category brings more controls, more evidence and more audit fee, every year from then on rather than once. Read the contract or questionnaire that triggered this and see whether it names a category. If it says only "SOC 2", it means Security. The criteria selector and scope builder tools walk the decision through, and SOC 2 requirements sets out what each category brings with it.

Type 1 and Type 2

A Type 1 reports on design, at a single point in time. The CPA firm examines the description of your system and forms an opinion on whether the controls are suitably designed to meet the criteria and were in place as of one specified date. The firm reads your policies, inspects your access configuration, looks at how change approval is set up, and concludes whether that design, if operated, would satisfy the criteria. What it does not do is test whether you actually operated anything. A Type 1 can be produced quickly because it needs no history, and it is what companies reach for when a contract is sitting unsigned and the customer will accept an interim position.

A Type 2 reports on design and on operating effectiveness, across a period. It includes everything a Type 1 does, then adds testing: the CPA firm samples evidence from across a stated observation window to check that each control actually ran when it was supposed to. Quarterly access reviews mean four reviews to produce. Change control means a sample of change tickets from across the period. The report names the period on its face and the opinion attaches to that period. This is the report enterprise vendor risk teams are built around, because it is evidence that the controls are a working practice rather than a written intention. It is also the one that can surface exceptions, since it is the only one that looks. Our Type 1 versus Type 2 page covers the sequencing question, including whether you need a Type 1 first.

What is actually inside a SOC 2 report

A report runs from forty to well over a hundred pages and has five recognisable parts. Knowing the shape makes an unfamiliar document readable in about twenty minutes.

1. Management's assertion
Your own statement, signed by your management, that the system description is accurate and that the controls were suitably designed and, for a Type 2, operated effectively across the period. It usually runs one to two pages and it is the foundation the rest of the report examines.
2. The independent service auditor's report
The opinion. Two or three pages on CPA firm letterhead, stating what was examined, against which criteria, over what date or period, and what the firm concluded. Read this first and read the final paragraph closely. An unqualified opinion is clean. A qualified opinion means something material was wrong, and the paragraph will say what.
3. The system description
The longest narrative part. It describes the services in scope, the infrastructure, software, people, procedures and data, the boundaries of the system, any subservice organizations, and the complementary user entity controls you expect customers to perform. It defines what the report covers, so a reader checking whether the product they buy is in scope checks here.
4. Controls, criteria and test results
The matrix, and the part reviewers spend the most time on. Each criterion, the controls mapped to it, the tests the CPA firm performed, and the result. In a Type 2 the tests describe sample sizes and procedures. Exceptions appear here in plain language, alongside management's response.
5. Other information provided by management
Optional and outside the scope of the opinion. Business continuity summaries, roadmap items and responses to prior-year findings live here. It is unaudited, and the report says so.

If you have just been sent one and need to assess it, how to read a SOC 2 report works through the same five sections from the reviewer's side, including the parts that most often hide a problem.

Who needs a SOC 2 and who does not

SOC 2 is voluntary. No Canadian statute requires it and no regulator issues it. It exists because buyers ask, which makes the question commercial.

You probably need one if you store or process other companies' data and any of these is true: a deal has stalled on a security review, a contract names SOC 2 with a date, your team fills in long questionnaires by hand every month, or you sell to financial services, health care or enterprise buyers. Companies reach this point somewhere between twenty and one hundred employees, usually pulled there by one large customer.

You probably do not need one if you sell to consumers, if no customer has ever asked, if you handle no customer data of consequence, or if the real request is a privacy law question rather than a security assurance one. It is also reasonable to decide the answer is not yet and to say so with a documented security position instead.

How long it takes, and the observation window

The timeline has three parts and only the first two respond to effort.

  1. Readiness, roughly eight to sixteen weeks. Scope the system, work out the gap between what you do today and what the criteria require, write the policies, turn on the controls, and get evidence generating automatically wherever it can. This is where nearly all the work sits for a first report.
  2. The observation window, three to twelve months, Type 2 only. A period during which you run the controls faithfully and they produce records. Three months is the shortest most CPA firms will issue over, six is the common first choice, twelve is where mature programs settle because it leaves no uncovered gap between consecutive reports.
  3. Fieldwork and reporting, four to ten weeks. The CPA firm requests evidence, tests samples, raises questions, and drafts the report. How clean your evidence package is drives most of the variance here.

The window cannot be compressed, backdated or bought. Evidence has to have genuinely existed during the period, with timestamps that show it, and an access review that never happened in the second quarter cannot be performed later and presented as though it had. A first Type 2 with a six month window lands near ten to twelve months end to end. A Type 1 runs roughly ten to fourteen weeks because it needs no window. The observation window planner works backwards from a customer deadline to the date your window has to open, and SOC 2 cost in Canada covers the money side.

SOC 1 and SOC 3 in a sentence each

SOC 1 reports on controls at a service organization that are relevant to its customers' financial reporting, which is what a payroll processor or a fund administrator is asked for, and it exists for the customer's own auditors rather than its security team.

SOC 3 is a short public summary of a SOC 2, with the system description trimmed and the control matrix and test results removed, which makes it safe to put on a website but far too thin to satisfy anyone doing real vendor review.

A buyer who asked for "a SOC report" and said nothing else almost certainly means a SOC 2 Type 2. Ask before commissioning anything: the three engagements are not interchangeable and the wrong one costs a year.

What SOC 2 does not cover

It is not privacy law compliance. Even a report that includes the Privacy category reports on commitments you made in your own privacy notice, judged against the AICPA's criteria. It does not assert that you comply with PIPEDA, Quebec's Law 25, PHIPA or any other statute. Those obligations apply whether or not anyone asks, and no attestation discharges them.

It is not a penetration test. The criteria expect a vulnerability management process, and the auditor looks for evidence that testing happens and findings get fixed. That is a check on the process, not on your posture. The CPA firm does not attack your application, and a clean report says nothing about whether somebody could break in.

It is not a guarantee, and it is not continuous. The opinion covers a stated scope on a stated date or period, using samples rather than every instance. Companies with clean reports have had breaches. The report is evidence that a control environment existed and was tested, which is useful and finite.

It is not a substitute for reading it. Scope can exclude the product a customer actually buys, subservice organizations can be carved out, and complementary user entity controls push real obligations back onto the customer. All of that is visible to anyone who opens the document.

Find a firm to do the work

Tell us your scope, your timeline and whether a customer has named a date. We will put it in front of Canadian firms that do SOC 2 readiness and audit work.

Get matched

You can also browse the directory of Canadian SOC 2 auditors and readiness firms, or start with the cost calculator and scope builder if you are still working out what you need. Readiness consultancies that publish their engagement model, including TrazTech, are listed there with the rest.

Common questions

Can we say we are SOC 2 certified?

No, because no such status exists. There is no accreditation body, no certificate and no registry for SOC 2. The accurate phrasing is that you have completed a SOC 2 Type 1 or Type 2 examination, name the period the report covers, and offer to share the report under NDA. Security reviewers notice the difference and it reads as a signal about how carefully you handle the rest.

Do we need a Type 1 before a Type 2?

No. Nothing in the standard requires it and many companies go straight to a Type 2. A Type 1 earns its cost only when a specific deal is waiting and the customer will accept an interim document, because it buys you something to show while the observation window runs. If nothing is waiting, the money is usually better spent on readiness.

Which Trust Services Criteria should we include?

Security only, unless a customer contract or questionnaire names another category in writing. Security is mandatory and covers what vendor security reviews actually ask about. Every additional category adds criteria, controls, evidence and audit fee, and it does so every year afterward, not just once. Categories can be added at a later renewal if a buyer asks.

How current does a SOC 2 report have to be?

Most buyers want a report whose period ended within the last twelve months. Between one period ending and the next report issuing there is a gap, and the usual answer is a bridge letter from management covering it. A report more than a year stale will be challenged by any serious vendor risk team, which is why annual renewal counts as ongoing cost.