A SOC 2, or System and Organization Controls 2 is an auditing framework from the American Institute of Certified Public Accountants (AICPA) that is designed to measure whether a service organization’s security controls meet five Trust Services Criteria (TSC): security, availability, processing integrity, confidentiality, and privacy (as applicable to the organization). The output is an audit report shared under NDA, not a public certificate.
Key takeaways
- SOC 2 is a voluntary AICPA auditing framework that tests whether a service organization’s security controls meet the Trust Services Criteria applicable to that organization.
- Type 2 is the enterprise standard because it demonstrates operational effectiveness of the selected controls over a 6+ month period, rather than at a snapshot in time.
- Security is the only required TSC; availability, processing integrity, confidentiality, and privacy are optional add-ons.
- SOC 2 produces an audit report shared under NDA, not a public certificate like ISO 27001.
- Expel holds an annual SOC 2 Type 2 (May 1–April 30) and provides Bridge Letters for interim periods.
While SOC 2 may have started as a niche request from tech-savvy procurement teams, it is typically now table stakes for any SaaS company selling to US enterprise buyers. Companies fielding vendor security questionnaires are increasingly likely to be asked for one—and if you only have a Type 1, you may have noticed it doesn’t always close the follow-up questions regarding operational effectiveness of controls.
SOC 2 sits within the broader cybersecurity compliance landscape, but it increasingly carries weight in US enterprise sales cycles. This page covers what SOC 2 typically tests, what separates Type 1 from Type 2, and what pursuing it may involve for security teams.
What does SOC 2 actually measure?
SOC 2 evaluates controls against up to five Trust Services Criteria which an organization chooses based on applicability. Security is the only required criterion—the others are optional.
The Security criterion maps to the AICPA’s Common Criteria (CC), which cover logical and physical access controls, change management, risk assessment, system operations, and incident response.
The four optional criteria—Availability, Processing Integrity, Confidentiality, and Privacy—are included based on service type. Many first-time programs start with Security.
SOC 2 Type 1 vs. Type 2: What’s the difference?
A Type 1 report is a point-in-time assessment. An auditor typically verifies that controls are designed appropriately on a single date, not that they worked consistently over time. It’s a useful starting point but does not demonstrate operational effectiveness of specific controls over a period of time.
A Type 2 covers a minimum 6-month observation period and tests whether controls operated effectively throughout the window. This is what most enterprise buyers mean when they ask for a SOC 2 because they are seeking assurance that a vendor’s controls are operating effectively before making a purchase decision.
What does a SOC 2 audit cover?
An organization defines the system boundaries—which infrastructure, products, and personnel are in scope—and an independent auditor typically tests controls within those boundaries. Scope directly affects the size of the report.
Depending on the TSC in scope, many Type 2 audits examine: logical access controls (who can access what, how access is provisioned and revoked, MFA enforcement); change management (how code and config changes are reviewed and deployed); incident response (how events are detected, escalated, and resolved); vendor management; and risk assessment processes.
The final report is an auditor’s opinion, not a pass/fail result. It describes what was tested and whether controls operated effectively during the observation period. Most organizations share it under NDA—unlike ISO 27001, there’s no public registry.
Who needs a SOC 2 report?
SOC 2 is voluntary. In practice, it’s a common expectation for any SaaS company or service provider selling to enterprise buyers in the US.
According to industry data, it’s now a common customer trust expectation for B2B SaaS companies and cloud service providers handling customer data; managed service providers—including MDR providers and MSSPs; data analytics, AI, and infrastructure companies; and any vendor whose platform sits inside a buyer’s security or compliance perimeter.
How long does SOC 2 take?
According to AICPA, Type 2 requires a minimum 6-month observation window. That clock starts once controls are in place and consistently operating. Many companies need 3–5 months before that to identify gaps, remediate them, and get everything documented.
A realistic path could look like: readiness assessment (4–8 weeks) for gap analysis against the Trust Services Criteria; remediation (8–16 weeks) to build or fix missing controls; audit window (6–12 months) where controls must operate consistently; and fieldwork and report (4–8 weeks) for auditor testing, additional remediation activity, and report drafting.
Most first-time SOC 2 programs receive their Type 2 report 12–18 months after starting. Companies with documented security policies, access reviews, and incident response playbooks already in place tend to shorten this.
How does Expel support SOC 2?
Expel holds a SOC 2 Type 2 with an annual audit period from May 1 to April 30. The report is available under NDA to customers and prospects on request, and Expel provides Bridge Letters for periods between annual reports to confirm there have been no material changes to the control environment. You can read all about our Compliance program here: https://expel.com/security-compliance/ and find all our compliance documentation within our Trust Center here: https://security.expel.com/
Sometimes when organizations are pursuing their own SOC 2 they underestimate the gap between having security controls and repeatable and reliably auditable ones. Policies need to be documented. Access reviews need to be evidenced. Incident response needs to be logged, attributed, and retrievable. The controls are often already in place—it’s the evidence collection that catches teams off guard.
Expel’s 24×7 monitoring generates the kind of timestamped, attributed records auditors typically want to see. Our 2.41-minute median time to detect and 14-minute mean time to remediate for fully automated high/critical incidents aren’t just performance metrics—they may be able to serve as evidence your auditors can point to.
Frequently asked questions
What is the difference between SOC 2 Type 1 and Type 2?
A SOC 2 Type 1 report verifies that controls are designed appropriately on a specific date. A Type 2 covers a minimum 6-month observation period and tests whether those controls actually operated effectively throughout. Most enterprise buyers require Type 2. A Type 1 is a useful starting point but typically generates follow-up questions about your Type 2 timeline.
What is SOC 2 certification?
SOC 2 produces an audit report, not a certificate. After an independent CPA firm completes the assessment, the organization receives a report attesting to whether controls met the Trust Services Criteria. This report is shared under NDA. It’s not publicly posted in a registry the way ISO 27001 certification is. When someone says ‘get SOC 2 certified,’ they typically mean receiving a Type 2 report.
What is a SOC 2 audit?
A SOC 2 audit is an independent examination of a service organization’s controls by a licensed CPA firm. The auditor evaluates controls against AICPA Trust Services Criteria and produces a report describing what was tested and—for Type 2—whether controls operated effectively during the audit period. The process includes evidence collection, controls testing, and auditor fieldwork.
Is SOC 2 required?
SOC 2 is voluntary.
How long does a SOC 2 audit take?
A SOC 2 Type 2 requires a minimum 6-month observation window, plus time for readiness assessment, remediation, and auditor fieldwork. Many organizations receive their first Type 2 report 12–18 months after starting the process. Companies that already have documented security policies and consistent evidence practices can shorten this.

