Independent auditor report

SOC 2

SOC 2 is a US attestation reporting standard developed by the AICPA — an independent CPA evaluates whether a service organization’s controls meet the Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

Start assessmentRead about the standard
51
controls in Guardiso
30
free-test questions
PL · EN
two languages

What is SOC 2?

SOC 2 (System and Organization Controls 2) is a reporting standard developed by the AICPA (American Institute of Certified Public Accountants). The outcome of the examination is not a certificate but an attestation report — a detailed document in which an independent CPA describes the service organization’s system and issues an opinion on its internal controls.

The evaluation is based on the Trust Services Criteria (TSC): security (the mandatory category, known as the Common Criteria CC1–CC9), and optionally availability, processing integrity, confidentiality, and privacy. The organization chooses the scope of categories that matches the commitments it makes to customers.

Unlike ISO 27001 certification, a SOC 2 report is a confidential document, typically shared with customers and partners under an NDA — there is no public “SOC 2 certificate”, even though the term is used colloquially.

Type I vs Type II

A Type I report evaluates the design of controls at a specific point in time — the auditor confirms that, as of a given date, the controls are suitably designed and implemented. It is the faster and cheaper option, often chosen as a first step.

A Type II report additionally evaluates the operating effectiveness of controls over an observation period, usually 3 to 12 months. The auditor tests samples of evidence from the entire period (for example deployments, access reviews, incident handling), which makes Type II significantly more valuable as assurance.

Mature buyers — especially enterprise customers in the United States — almost always expect a Type II report. The typical path is a Type I to start, followed by annual Type II reports covering successive observation periods.

Who needs it?

SOC 2 is not a legal requirement — it is a market standard enforced by customers. It primarily applies to service organizations that process or store customer data: SaaS companies, cloud and hosting providers, data centers, outsourcing firms, and fintechs.

In practice, a SOC 2 report becomes table stakes for companies selling to customers in the United States and to the enterprise segment. Procurement and security teams at large organizations require a SOC 2 report (or an ISO 27001 certificate) as part of vendor due diligence — not having one can block a deal or significantly lengthen the sales cycle.

For European SaaS companies planning to expand into the US market, SOC 2 is a natural complement to ISO 27001 — the two frameworks overlap substantially in controls, so the second one is much faster to implement than the first.

What does the examination look like?

A SOC 2 examination can only be performed by an independent licensed CPA (Certified Public Accountant) firm, working under AICPA attestation standards. The auditor must be independent of the examined organization — they cannot both advise on the implementation and issue the opinion.

The process starts with scoping: the system description, the selected Trust Services categories, and the observation period. The auditor then collects and tests evidence — policies, configurations, logs, samples of changes and incidents — and interviews the team. A readiness assessment is a common preliminary step, identifying gaps to close before the actual examination.

The result is a report containing the auditor’s opinion (the attestation letter), management’s system description, the list of controls, and test results with any exceptions. An unqualified opinion means the controls meet the criteria; customers evaluate any exceptions described in the report on their own.

How does Guardiso help?

Guardiso includes the complete set of Trust Services Criteria (51 criteria with their Points of Focus) as ready-made controls described in both Polish and English. Enabling the framework automatically seeds the controls in your organization, and cross-mapping shows which requirements you already cover through ISO 27001 or other implemented standards.

Automated evidence collection from integrations (cloud providers, code repositories, HR systems, and security tools) builds a continuous evidence base — critical for a Type II report, where the auditor tests control effectiveness across the entire observation period, not just on the day of the examination.

The readiness self-assessment, risk register, policy management, and remediation tasks guide you from the first gap analysis to full readiness before the examination. When the CPA auditor asks for evidence, everything is in one place — organized by TSC criteria and ready to share.

Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
SOC 2 readiness score
0/30 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards