SOC 2

Vendor-neutral guidance on the SOC 2 examination for founders, CTOs, CISOs, engineering leads, and compliance owners — what the report proves, the Type I / Type II split, readiness through fieldwork, cost and timeline drivers, exceptions and opinion types. SOC 2 is an AICPA SSAE 18 attestation examination performed by a licensed CPA firm, not a certification. Not legal advice. Does not determine that YOU need SOC 2. Does not issue a SOC 2 report.

What is SOC 2, and what does the report prove?

SOC 2 is an AICPA SSAE 18 attestation examination over the Trust Services Criteria — a licensed CPA firm's report, not a certification. Not legal advice.

SOC 2 Type I or Type II — which report do you need?

SOC 2 Type I covers control design at a point in time; Type II covers operating effectiveness over a review period. Most buyers want Type II. Not legal advice.

Who needs SOC 2, and is it ever legally required?

No statute requires a SOC 2 report — the trigger is enterprise procurement and contracts. How to tell whether SOC 2, ISO 27001, or neither fits. Not legal advice.

How do you get a SOC 2 report, step by step?

The SOC 2 lifecycle end to end: scope criteria, gap assessment, remediation, engage a CPA firm, observation period, fieldwork, report. Not legal advice.

What belongs on a SOC 2 readiness checklist?

A SOC 2 readiness checklist by criteria series CC1–CC9, with every item labelled as an attestation requirement, best practice, or recommendation. Not legal advice.

What happens during a SOC 2 audit?

What a CPA firm does during a SOC 2 examination: planning, walkthroughs, populations, sampling, testing, and report drafting under SSAE 18. Not legal advice.

Who can perform a SOC 2 examination and issue the report?

Only a licensed CPA firm can perform a SOC 2 examination and issue the report. How to verify a licence and peer review, and why tooling is not the attestor.

What evidence will a SOC 2 auditor request?

The evidence a SOC 2 auditor requests, by criteria series CC1–CC9: populations, access reviews, change approvals, incident records. Not legal advice.

How long does SOC 2 take from start to report?

SOC 2 timelines by stage: readiness, the Type II observation period of commonly 3–12 months, fieldwork, and report drafting. Market observation, not a rule.

How much does SOC 2 cost, and what drives the price?

SOC 2 cost drivers: CPA firm fee, readiness and tooling, penetration testing, internal time. One-time versus recurring, as market observation — not a quote.

What happens if you have SOC 2 audit exceptions?

An exception is a control deviation noted in a SOC 2 report — not automatically a qualified opinion. How management responses work, and who decides. Not legal advice.

What happens if you fail SOC 2?

SOC 2 has no pass or fail — it produces an opinion: unmodified, qualified, adverse, or a disclaimer. What each means and how to recover. Not legal advice.

How do you choose a SOC 2 auditor?

Defensible criteria for selecting a SOC 2 auditor: CPA licence, peer review, independence, relevant experience, report quality, timeline, price. No rankings.

How do you prepare engineering teams for SOC 2?

SOC 2 for developers and DevOps: pull-request approvals, access provisioning, secrets, logging, backups, on-call — what is tested and what is just good practice.

How do you collect SOC 2 evidence continuously?

Why a Type II period needs evidence across the whole window, what a sensible collection cadence looks like, and why automation supports but never replaces the CPA exam.

How does ShipReady Metrics support SOC 2 evidence?

Which SOC 2 criteria series ShipReady Metrics helps evidence, which it does not touch, and where the licensed CPA firm's examination begins. Not legal advice.