Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do you get a SOC 2 report, step by step?

Last verified

Seven phases: choose the criteria and system boundary, run a gap assessment, remediate, engage a licensed CPA firm, run the observation period if you want a Type II, support fieldwork, then receive the report. You do the first three; only the CPA firm performs the examination and issues the opinion.

How to get a SOC 2 report, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.

This is the lifecycle, not YOUR project plan

Audience: an engineering lead, CTO, CISO, or compliance owner who has been handed SOC 2 and needs to know what the path actually looks like. This page sequences the work. It does not determine that YOU need SOC 2, does not scope YOUR examination, and does not issue a SOC 2 report.

SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report, so there is no filing deadline and no clock. Your dates come from a customer commitment and from your CPA firm's calendar. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate, and the phase that produces the deliverable is a CPA firm issuing a report, not a body granting a certificate.

Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period. That choice determines whether phase five exists at all. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor. Last verified 10 September 2026. Not legal advice.

The seven phases

Numbered because order matters: remediating before scoping wastes work, and engaging a firm before you can describe your system wastes their time and your money.

SOC 2 lifecycle by phase, with the organisation / CPA-firm split (paraphrase of the attestation standards; not legal advice)
PhaseWhat happensWho does itKind of text
1. ScopeChoose the criteria categories (the common criteria always, plus any of Availability, Confidentiality, Processing Integrity, Privacy a customer requires) and draw the system boundary: services, infrastructure, software, people, procedures, and data. Decide which subservice organisations are carved in or carved out.You. A CPA firm will advise on scoping questions, but the description is yours.Attestation-standard requirement that the description be fair and that you assert it.
2. Gap assessmentCompare what you actually do against the criteria in scope, control by control. Produce a gap list with owners.You, sometimes with a readiness adviser. If the adviser is a CPA firm, ask how they preserve independence for the examination.Best practice — no attestation standard requires a gap assessment, and skipping it is not an exception.
3. RemediateImplement or fix controls, write the policies you are missing, and start generating evidence. Confirm evidence is actually being captured, not just that the control exists.You.Best practice for how; the underlying controls exist to satisfy criteria, which is a Trust Services Criteria reference.
4. Engage a licensed CPA firmSelect and contract the firm, agree report type, criteria in scope, period dates, fieldwork window, and report turnaround. Verify the licence and ask about peer review.You choose; only a licensed CPA firm can accept the engagement.Attestation-standard requirement — the practitioner must be independent and competent to perform the examination.
5. Observation period (Type II only)Controls run and evidence accumulates across the agreed window. Populations must be complete for the whole period, not just its end.You operate; the firm tests afterwards.Attestation-standard requirement that operating effectiveness be examined across the stated period.
6. FieldworkThe firm plans, walks through controls, requests populations, selects samples, tests, and raises questions and possible exceptions.The CPA firm performs it; you support it.Attestation-standard requirement — the procedures are the practitioner's judgement, not your preference.
7. ReportThe firm drafts, you review the description and provide management responses to any exceptions, and the firm issues the report with its opinion.The CPA firm issues it. You cannot issue your own.Attestation-standard requirement — the opinion is the practitioner's under AT-C section 205.

Checklist per phase

One short list per phase, so a first-time team can see the exit condition rather than a vague "be ready".

  • Phase 1 exit: a written system description draft, the criteria categories chosen with the customer requirement that justified each, and a named accountable owner. Attestation-standard requirement for the description; the rest is best practice.
  • Phase 2 exit: a gap list where every gap has an owner and a date, and the criteria series each gap relates to. Best practice.
  • Phase 3 exit: each remediated control has produced at least one dated piece of evidence in the way it will produce evidence every time. Best practice, and the single biggest predictor of a calm fieldwork.
  • Phase 4 exit: a signed engagement letter, a verified CPA licence, agreed period dates, and a report-delivery estimate in writing. Attestation-standard requirement that a practitioner be engaged; verification is best practice.
  • Phase 5 exit: the period closed with complete populations retrievable for every in-scope control. Attestation-standard requirement in effect.
  • Phase 6 exit: every request-list item answered, every possible exception discussed while there is still time to gather evidence. Best practice.
  • Phase 7 exit: the report in hand, the opinion type understood, and management responses recorded for any exceptions. Attestation-standard requirement that the report contain the opinion.

What only a licensed CPA firm can do

This split is where first-time teams lose the most money — usually by buying tooling or advisory and believing the examination is covered.

  • Perform the SOC 2 examination and issue the report containing the opinion. Only a licensed CPA firm. Attestation-standard requirement.
  • Decide which procedures to perform, how to sample, and what constitutes sufficient appropriate evidence. The practitioner's professional judgement, not yours.
  • Conclude that a deviation is an exception, and decide whether the opinion is modified. Attestation-standard requirement under AT-C section 205.
  • Everything else — scoping, the description, policies, controls, evidence, remediation, populations — is yours, and tooling can help with all of it.
  • Compliance-automation tooling, including this product, is not the attestor: it does not issue an opinion, does not sign a report, and does not replace the examination.

Kinds of text on this page

Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.

How to read the claims on this page (not a ranking; not legal advice; last verified 10 September 2026)
Kind of textWhat it meansWhat it is not
Attestation-standard requirementSSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination.Not a statute, and it binds the practitioner rather than you.
Trust Services Criteria referenceA pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100.Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase.
Best practiceWhat experienced practitioners commonly do to reach fieldwork without a scramble.Not required by any attestation standard. Skipping it is not an exception.
Market observationWhat buyers, contracts, and firms are commonly observed to do — including sequencing and lead times.Not a rule, not a quote, and not a promise about YOUR deal, timeline, or price.
SRM recommendationSomething this product suggests doing.Not a legal requirement, not an attestation requirement, and not an audit opinion.

What to do now

For a first-time team with a deal waiting, this is the shortest honest path. It assumes nothing is in place except the desire for a report.

  • Write down the customer requirement: report type, criteria categories, and the date they need it. Everything downstream is derived from that.
  • Draft the system description in one page before doing anything technical. If you cannot describe the boundary, you cannot scope the examination.
  • Run the gap assessment against the criteria in scope and accept the result honestly. A short gap list from a narrow, truthful boundary beats a wide boundary you cannot evidence.
  • Talk to at least two licensed CPA firms early, even before remediation is finished, to learn their lead times. Verify each licence with the relevant state board of accountancy.
  • Decide Type I or Type II, then set the period start date and instrument evidence capture before it opens.
  • Name one accountable human for the examination and give them the time. Diffuse ownership is the most common cause of a slipped fieldwork date. SRM recommendation.
  • Do not promise a customer a report date until fieldwork is booked and the firm has stated its turnaround.

Checklist

The cluster's wayfinding list. Each item points at the phase that owns it, labelled by kind of text.

  • Criteria categories chosen and justified by a customer requirement? Trust Services Criteria reference — read TSP section 100 for the criteria themselves.
  • System boundary written, including subservice organisations carved in or out? Attestation-standard requirement that the description be fair.
  • Gap list closed or accepted with owners and dates? Best practice.
  • Licensed CPA firm engaged, licence verified, peer-review status asked about? Attestation-standard requirement plus best practice.
  • Report type and period dates agreed in writing? Attestation-standard requirement that the report state them.
  • Evidence capture proven working before the period opens? Best practice — and the thing that decides whether fieldwork is calm.
  • Named accountable owner with time allocated? SRM recommendation.
  • Nobody has promised a customer a date the CPA firm has not confirmed? Market observation about how commitments slip.

Where this shows up in ShipReady Metrics

The bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set that is an illustrative readiness mapping to be tailored by a compliance owner — not the criteria and not an audit programme.

If you already have a session: the gap-assessment and remediation phases are what this product is for. Evidence collection gathers artefacts, evidence review with the met-verdict overlay records a human judgement per control, the policies library holds the documents phase three usually reveals are missing, and the 24-framework crosswalk maps SOC 2 to canonical controls by criteria series reference only, without reproducing Trust Services Criteria text. Connector-sourced evidence — dependency, code-scanning, and secret-scanning ingest — feeds the engineering side. ShipReady Passport and the auditor share token hand a reviewer a scoped view during phase six. The cyber risk register lives under the security area.

The obligation map lists frameworks the organisation has marked in-scope, including soc2 if that mark is set; that mark is not a determination that a buyer requires SOC 2. Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.

Primary sources (last verified 10 September 2026)

Phase mechanics come from the AICPA sources below. Sequencing advice and lead-time comments are labelled best practice or market observation because no authority publishes them as rules.

AICPA Trust Services Criteria, TSP section 100 — 2017 Trust Services Criteria with the 2022 revised points of focus. Proprietary AICPA material: cited by reference and paraphrased, never reproduced. AICPA attestation standards SSAE 18, AT-C section 105 and AT-C section 205. AICPA SOC 2 guidance for service organisations. AICPA Peer Review Program and the state boards of accountancy for practitioner licensing. These are not a complete list, and none of them is legal advice.

The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.

Frequently asked questions