All frameworks
SOCType I & II

SOC 2 compliance

The trust report North American buyers ask for.

SOC 2 is an attestation, performed by a licensed CPA firm, against the AICPA Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. A Type I report assesses design at a point in time; Type II assesses operating effectiveness over a period.

Start from the basics

The standard

SOC 2 — AICPA Trust Services Criteria

Who needs it

SaaS and technology vendors — particularly selling into the US — whose customers require independent assurance over how they safeguard data.

5

Trust Services Criteria covered

The basics

What is SOC 2?

SOC 2 is a report, not a certificate. A licensed CPA firm examines your controls against the AICPA's Trust Services Criteria and writes an independent opinion your customers can read and trust. It's become the de-facto security credential for software companies in North America.

A Type I report says your controls are well-designed at a point in time; a Type II says they actually operated effectively over a period — usually three to twelve months. Most serious buyers want the Type II, because it proves you don't just look secure on paper for a single day.

Why it matters

What SOC 2 does for your business

It closes deals

"Do you have your SOC 2?" is often the first question from a prospect's security team. Having the report ready turns a weeks-long security review into a quick attachment.

It moves you up-market

Enterprises won't buy without it. A SOC 2 is your ticket into the rooms where the bigger budgets live.

It builds durable trust

An independent CPA's opinion carries weight a self-assessment never will — third-party proof, not a promise.

What it covers

Trust Services Criteria

Security (required) plus any of Availability, Confidentiality, Processing Integrity and Privacy.

Type I vs Type II

Design at a moment (I) versus operating effectiveness across a window, usually 3–12 months (II).

Evidence over time

Type II demands sampled evidence throughout the period — continuous collection is essential.

Auditor-ready workflows

Access reviews, change management and incident response mapped to the criteria.

The hard way

The killer with SOC 2 is the Type II window: you need months of continuous, timestamped evidence, collected while you're also running the business. Reconstructing that by hand the week before the audit is exactly where teams burn out.

The easier way, with Compliance One

  • Maps your controls to the Trust Services Criteria and flags gaps before your auditor does.
  • Continuously captures timestamped evidence across the full Type II observation window.
  • Automates recurring tasks — access reviews, vendor reviews — so nothing lapses mid-period.
  • Reuses the same evidence to satisfy ISO 27001 and other frameworks in parallel.

Do it once, reuse it everywhere. Evidence you collect for SOC 2is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Type I or Type II first?
Many start with a Type I to show design quickly, then move to Type II. If your buyers can wait, going straight to Type II saves a step — and Compliance One collects evidence continuously, so the window takes care of itself.
Which Trust Services Criteria do we need?
Security is mandatory; you add Availability, Confidentiality, Processing Integrity or Privacy based on what you promise customers. We help you scope the right ones.
How much evidence is this really?
A lot — access reviews, change logs, monitoring, vendor reviews — sampled across the whole period. Automating collection is the difference between a calm audit and a fire drill.
Does SOC 2 help with ISO 27001?
Enormously. The control sets overlap, so the evidence you gather for SOC 2 covers much of ISO 27001 — do it once, prove it in both.

Ready to tackle SOC 2?

See exactly how Compliance One maps SOC 2 to your environment in a 30-minute walkthrough — and how much of it we handle for you.