Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Who needs SOC 2, and is it ever legally required?
Last verifiedNobody is required by law to have a SOC 2 report. The trigger is commercial: enterprise procurement, vendor-risk review, and contract clauses. It typically matters for business-to-business software that stores or processes customer data. Regulatory regimes such as HIPAA and PCI DSS are a different question entirely.
Who needs SOC 2, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
This is the demand pattern, not YOUR obligation
Audience: a founder facing a first enterprise deal, a CTO or CISO planning a compliance budget, a compliance owner triaging frameworks, or an investor asking why a portfolio company has no report. This page describes when SOC 2 is commonly demanded. It does not determine that YOU need SOC 2, does not read YOUR contracts, and does not issue a SOC 2 report.
SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report. There is no regulator that fines you for not having one, no filing deadline, and no clock. What exists is a buyer who will not sign, a security questionnaire you cannot answer, or a contract you already signed promising a report by a date. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor.
"SOC 2 certified" is a misnomer — there is no SOC 2 certificate — and the misnomer matters here, because buyers who ask for "certification" often actually want a Type II report covering a recent period. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period. Clarify which the buyer means before you budget. Last verified 10 September 2026. Not legal advice.
Market pressure versus legal obligation
The distinction below is the whole point of this page. Getting it wrong in either direction wastes money: treating SOC 2 as a legal duty leads to premature spend; treating a regulatory regime as optional because you have a SOC 2 report leads to real exposure.
| Instrument | What creates the pressure | Kind of text | What it is not |
|---|---|---|---|
| SOC 2 | A buyer's procurement or vendor-risk process, a security questionnaire, or a clause in a contract you signed. | Market observation — no statute requires a SOC 2 report. | Not a legal requirement. Not a certificate. Not enforced by a regulator. |
| ISO/IEC 27001 | The same commercial pressure, more often outside the United States, plus buyers who prefer a certificate and a surveillance cycle. | Voluntary standard — market-driven, not a statute. | Not an AICPA attestation, and not interchangeable with a SOC 2 report. |
| HIPAA | United States law where protected health information is handled by a covered entity or business associate. | Legal requirement where it applies — enforced by a regulator, with its own breach-notification duties. | Not satisfied by a SOC 2 report. A SOC 2 report is not a HIPAA determination. |
| PCI DSS | Card-brand and acquirer contracts where payment card data is stored, processed, or transmitted. | Scheme and contractual requirement with its own validation regime. | Not satisfied by a SOC 2 report, and its assessors are not SOC 2 practitioners. |
| GDPR and similar data-protection law | Statute, wherever it applies to your processing. | Legal requirement where it applies — a question for counsel on your facts. | Not discharged by adding the Privacy category to a SOC 2 examination. |
Decision path by customer profile and data sensitivity
Walk the questions in order and stop at the first clear answer. This is a decision aid. It is not a determination, and the honest outcome for many early companies is "not yet".
- Has a real prospect asked, in writing, for a SOC 2 report? If yes, the question is no longer whether but which type and by when. Market observation.
- Have you already signed a contract promising a report by a date? Then this is a commercial commitment to your counterparty. Ask counsel what the clause actually obliges — that is a contract question, not an attestation question.
- Do you store, process, or transmit customer data that would hurt your customer if exposed? The more sensitive the data and the more privileged your access, the earlier the demand tends to arrive. Market observation.
- Who are your buyers? Enterprise and regulated-industry buyers with formal vendor-risk programmes ask early; small-business and self-serve buyers frequently never ask. Market observation.
- Are your buyers primarily outside the United States? Some prefer ISO/IEC 27001 certification. The SOC 2 versus ISO 27001 comparison on this site walks that trade-off; naming ISO 27001 elsewhere in prose is not a link to a docs cluster we have not published.
- Is the pressure actually a regulatory regime such as HIPAA or PCI DSS wearing the wrong name? Then a SOC 2 report is not the answer, and buying one first is a sequencing error. Ask counsel.
- Nobody has asked and no contract obliges you? Then a SOC 2 examination is a discretionary investment. Best practice is to build the underlying controls anyway and defer the examination until a deal needs it.
What SOC 2 does and does not unblock
Buyers use the report for a narrow purpose. Expecting more from it is the most expensive misunderstanding in this cluster.
- It answers a vendor-risk reviewer's question with an independent opinion instead of your own questionnaire answers. Market observation.
- It shortens security review because the reviewer reads a report they already know how to read. Market observation.
- It does not make you secure. An unmodified opinion is a statement about described controls against criteria, not a guarantee.
- It does not cover systems, products, or regions you left outside the description. Buyers do check the boundary.
- It does not replace a penetration test, a vulnerability-management programme, or a data-processing agreement.
- It does not discharge a statutory duty. No statute requires a SOC 2 report, and none accepts one in place of its own requirements.
Kinds of text on this page
Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination. | Not a statute, and it binds the practitioner rather than you. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | What experienced practitioners commonly do before committing to an examination. | Not required by any attestation standard. Skipping it is not an exception. |
| Market observation | What buyers, contracts, and firms are commonly observed to do — including who asks for a report and when. | Not a rule, not a quote, and not a promise about YOUR deal, timeline, or price. |
| SRM recommendation | Something this product suggests doing. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
Spend on evidence of demand before spending on an examination. The order below keeps the investment tied to revenue.
- Collect every written request and contract clause that mentions SOC 2, and note the report type and date each one asks for.
- Ask each requester whether a Type I plus a committed Type II date would unblock the deal now.
- Ask counsel whether any regulatory regime — not SOC 2 — is actually in play for the data you handle. That answer changes priorities.
- If buyers are mostly outside the United States, price ISO/IEC 27001 certification alongside SOC 2 before committing.
- If nobody has asked, build the controls and keep the evidence, and revisit the examination when a deal requires it. Best practice, not a rule.
- Do not let a compliance-automation purchase stand in for the engagement. Only a licensed CPA firm can perform the examination and issue the report.
Checklist
A qualification checklist, labelled by kind of text. Not a determination that you need a report.
- Do we have a written customer request or contract clause naming SOC 2? Market observation.
- Do we know which report type and which period the requester expects? Attestation-standard requirement that the report state type and period.
- Have we asked counsel whether a statutory or scheme regime applies to the data we handle? Legal requirement where it applies — counsel answers, not this page.
- Have we compared SOC 2 against ISO/IEC 27001 for our buyer geography? Best practice.
- Do we know which optional criteria categories a customer actually requires beyond the common criteria? Trust Services Criteria reference.
- Is there a named owner and a budget, or are we exploring? SRM recommendation.
- Have we stopped describing a future report as "certification" in sales material? Best practice — the misnomer damages credibility with careful reviewers.
Where this shows up in ShipReady Metrics
The obligation map lists frameworks the organisation has marked in-scope, including the bundled framework key soc2 if that mark is set. Marking soc2 in-scope is a record of your own intent. It is not a determination that a buyer requires SOC 2, not a legal determination, and not a scope decision for an examination.
If you already have a session: the soc2 framework is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set to be tailored by a compliance owner. ShipReady Passport and the auditor share token let you hand a prospect a scoped posture view before any report exists — useful during a security review, and explicitly not a SOC 2 report. Evidence collection, evidence review with the met-verdict overlay, the policies library, and the 24-framework crosswalk (criteria series references only, no Trust Services Criteria text reproduced) support the work that follows if you do proceed.
Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
Claims about the examination come from the AICPA sources below. Claims about who asks for a report are labelled market observation, because no authority publishes that as a rule.
AICPA Trust Services Criteria, TSP section 100 — 2017 Trust Services Criteria with the 2022 revised points of focus. Proprietary AICPA material: cited by reference and paraphrased, never reproduced. AICPA attestation standards SSAE 18, AT-C sections 105 and 205. AICPA SOC 2 guidance for service organisations. ISO/IEC 27001:2022 is a different instrument and a certifiable management-system standard. HIPAA and PCI DSS are separate regimes with their own enforcement paths. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.