THE USEFUL PART
Start with the decision your customer needs to make. Then agree the system, report type, responsibilities, and dates that will support it.
Understand what you’re working toward
A SOC 2 is an independent auditor’s report about a described system and its controls. It is an attestation, not a certification or a guarantee that a business cannot have a security incident. In the US context, a licensed CPA firm issues the opinion.
Management still owns the system, the controls, and the evidence. A compliance platform can organize that work. Its dashboard cannot stand in for the auditor’s conclusion.
Source context: AICPA — Trust Services Criteria; Schellman — Understanding SOC reports: Type 1 vs. Type 2; AICPA staff — Effects of software tools on SOC 2 examinations
Ask what the customer actually needs
Our starting recommendation: ask the person reviewing your business which service the report needs to cover, which report type they expect, and when they need it. A deadline for signing a contract is different from a deadline for receiving an issued report.
- Which product or service is being assessed?
- Is a Type 1 acceptable, or is Type 2 required for their decision?
- Which scope, covered dates, and additional information do they expect?
- Who can confirm these expectations in writing?
Make the scope concrete
Map the people, systems, data, and external services that support the service you are describing. Select the relevant Trust Services Criteria based on the service’s commitments and risks. The categories are Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Adding categories changes the work. It does not automatically make a report more useful to a customer. Discuss boundaries and dependencies with your auditor before treating a proposal as settled.
Source context: AICPA — Trust Services Criteria; Linford — Defining SOC 2 audit scope
Give the work an owner
Our practical suggestion is to name one program owner, then give each recurring control a person responsible for operating it and retaining evidence. Put readiness, the covered period, fieldwork, and report delivery on the same plan.
Use that plan to request comparable proposals. You will be better placed to understand what a platform, an adviser, and an auditor each contribute—and which work remains with your team.
THE EVIDENCE BEHIND THE EXPLANATION
Sources & editorial notes
Reviewed September 22, 2026. This guide draws on public criteria and practitioner explanations. Our suggested questions and planning frameworks are editorial analysis. Provider guidance is identified as such; it is not a universal requirement.
- AICPA — Trust Services Criteria ↗
2017 criteria with revised points of focus (2022). Formal criteria; public source.
- Schellman — Understanding SOC reports: Type 1 vs. Type 2 ↗
CPA-firm explanation of report coverage. Practitioner guidance, not the underlying standard.
- AICPA staff — Effects of software tools on SOC 2 examinations ↗
2021 public staff FAQs; explicitly nonauthoritative. Explains management and auditor responsibilities.
- Linford — Defining SOC 2 audit scope ↗
CPA-firm explanation of system boundaries and scoping decisions.
We have not reviewed a private SOC 2 report for this guide. General editorial information, not audit, accounting, or legal advice. Our editorial approach.
Suggest a correction