Type II ยท AICPA TSC
SOC 2
SOC 2 is the report your buyer's procurement team asks for before they will sign. The work is not writing policies. It is producing a year of evidence that the controls you claim actually ran.
What the engagement covers
SaaS and service providers holding customer data. Typical timeline: 8 to 12 weeks to audit ready.
- Trust Services Criteria scoping, so you are not audited on categories you never needed
- Control design mapped to the systems you already run, not a generic template
- Evidence automation for access reviews, change management and monitoring
- Auditor selection, readiness assessment and support through fieldwork
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Gap assessment against the selected criteria
- Remediation and evidence collection
- Observation window
- Type II report issued
Related reading
- Placeholder: SOC 2 article
Pulled from the legacy archive until this section is migrated.
- Placeholder: SOC 2 article
Legacy URL preserved.
Common questions
Do we need SOC 2 Type I or Type II?
Type I reports on control design at a point in time. Type II reports on whether those controls actually operated over a window, usually three to twelve months. Enterprise buyers almost always mean Type II. Type I is worth doing only when a deal needs evidence of progress before the observation window can close.
How long does a SOC 2 take?
Eight to twelve weeks to be audit ready, then the observation window itself, then fieldwork. An organization starting from nothing should plan on six to nine months before a Type II report exists. The readiness work is the part that compresses. The observation window is not.
Why do SOC 2 audits fail?
Almost never because a policy was missing. They fail because the evidence that a control ran does not exist. Access reviews nobody performed, change approvals nobody recorded, logs that rolled off before the window closed. Evidence has to be generated as operations happen, not assembled afterwards.
START HERE
Do not guess how far away you are.
A scored assessment against the SOC 2 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.