Criteria selection
Deciding which Trust Services Criteria belong in scope based on what you actually contract to deliver, rather than including all five because the list exists.
Attestation report
Getting the evidence running before the audit window opens, which is most of what determines whether a Type 2 goes well.
Who this applies to. SaaS and service organizations answering customer due diligence, usually because a deal is blocked on it.
SOC 2 is an attestation performed by a CPA firm against the Trust Services Criteria. Security is always in scope. Availability, confidentiality, processing integrity, and privacy are added when they are relevant to what you sell, and each one added is more work, so the selection is worth deliberating rather than defaulting.
The Type 1 and Type 2 distinction matters more than it first appears. Type 1 tests whether controls are designed appropriately at a point in time. Type 2 tests whether they operated effectively across a period, typically three to twelve months. That period is the constraint: if your evidence collection is not already running, the clock has not started.
Organizations that come to us with a signed audit engagement and a deal closing in ninety days are usually looking at a Type 1 now and a Type 2 later. That is often the right answer, and it is better to say so early than to discover it during fieldwork.
The engagement
Deciding which Trust Services Criteria belong in scope based on what you actually contract to deliver, rather than including all five because the list exists.
Measuring the current environment against the criteria and producing a gap register tied to specific points of focus, so remediation is a work list rather than a research project.
Establishing how each control produces evidence automatically and where it lands. This is the difference between a Type 2 that is administratively routine and one that consumes a quarter of someone’s year.
Choosing when the period starts and how long it runs, working backwards from the date a customer needs the report in hand.
Preparing for fieldwork and sample requests, so the auditor gets what they ask for first time. You engage the CPA firm directly, and their independence is what makes the report mean something.
What you are left holding
FAQ
Type 2 is what customers generally want, because it says the controls worked over time rather than existed on one day. Type 1 is a reasonable staging post when a deal needs something now and the observation period has not run.
If you have the runway, going straight to Type 2 avoids paying for two engagements.
No. A SOC 2 examination is performed by a licensed CPA firm. We prepare you for it. Preparing an organization and then attesting to it would be the conflict the report exists to avoid.
Considerably. The control work overlaps heavily and a functioning ISMS produces much of the evidence a SOC 2 auditor will ask for. The mapping is not one to one, and the reporting formats differ, but you are starting from a much better position than an organization with neither.
Reviewed July 31, 2026. Primary sources: AICPA, SOC 2 and the Trust Services Criteria .
The first conversation is about what is actually in scope, because that governs the cost of everything after it.