What SOC 2 certification actually requires

SOC 2 certification means an independent auditor has verified that your company controls data security, availability, processing integrity, confidentiality, and privacy according to standards set by the American Institute of CPAs. You do not get certified by a government body — a licensed auditor from a Big Four firm or a smaller audit shop conducts the review and issues a report. The report itself is what clients see, not a badge or certificate you hang on a wall.

The process takes between four and nine months from start to finish, depending on how organized your systems already are. If you have no documentation of your security practices, you are looking at the longer end. If you have already been running security controls and keeping records, you can move faster. The cost ranges from $15,000 to $100,000 or more, depending on company size and audit firm rates.

There are two types: Type I (a snapshot of your controls at one point in time) and Type II (proof that your controls worked consistently over at least six months). Most clients ask for Type II because it shows your practices are not just theoretical.

Key Takeaways

  • SOC 2 requires an independent auditor to review your security controls, not a self-assessment or online checklist.
  • You must document every control you claim to have — policies, procedures, evidence of execution — before the audit begins.
  • Type II audits take six months minimum because the auditor must observe your controls working over time, not just once.
  • Hiring an audit firm early to scope the work and identify gaps costs less than discovering problems mid-audit.
  • The biggest time sink is usually gathering evidence that controls actually ran, not designing the controls themselves.

Start by scoping the audit with a may have access to firm

Do not design your entire control structure and then call an auditor. Call an auditor first. A pre-audit consultation with a SOC 2 firm costs $2,000 to $5,000 and takes a few hours, and it tells you exactly what you need to do before they show up to audit. They will walk through your current setup, identify what controls are missing or poorly documented, and give you a timeline and cost estimate.

This step saves months because you avoid building controls the auditor will reject. Many companies spend weeks documenting something that does not meet the standard, then have to redo it. A scoping call prevents that. The auditor will also tell you whether your company is even ready for SOC 2 — if you have no formal security program at all, they may recommend you spend three to six months building one before paying for the audit.

Choose a firm that has done audits in your industry. A firm experienced with SaaS companies will move faster than one that mostly audits banks. Ask for references from recent clients and call them — ask how long the audit took and whether the firm was responsive when questions came up.

Document every control before the auditor arrives

The auditor does not care whether your controls are perfect. They care whether you have written them down, whether you follow them, and whether you have evidence that you followed them. A control that exists only in someone's head is worthless for SOC 2.

For each control, you need: a written policy (what you are supposed to do), a procedure (how you actually do it), and evidence (logs, screenshots, sign-off sheets, or records showing you did it). If your policy says "we review access rights quarterly," you need the actual quarterly review documents, signed and dated. If your policy says "we encrypt data in transit," you need network diagrams, configuration screenshots, or a penetration test showing encryption is on.

Start with the five trust service criteria: security (protecting data from unauthorized access), availability (systems are up when needed), processing integrity (transactions are accurate and complete), confidentiality (sensitive data stays private), and privacy (personal data is handled as promised). Map your existing controls to these categories. You will probably find you have some controls but they are not documented. Document them. You will also find gaps — controls you do not have at all. Build those or decide to accept the risk and note it in your audit.

Use a spreadsheet or a control management tool to track this. List the control, the policy document, the procedure document, and the evidence you have gathered. This becomes your audit workpaper and saves the auditor time, which saves you money.

Assign one person to own the audit timeline

SOC 2 audits stall when no one is clearly responsible for answering the auditor's questions and gathering evidence. Assign one person — ideally someone in security, compliance, or operations — to be the single point of contact. This person coordinates with engineering, finance, HR, and other departments to pull documents, answer questions, and provide evidence.

The auditor will send you a detailed request list. It will ask for things like: access control logs for the past six months, change management records, incident response logs, employee training records, vendor risk assessments, and disaster recovery test results. If no one is tracking these requests, they pile up and the audit slows down. The owner keeps a checklist, follows up with each department, and sends everything to the auditor on schedule.

This role does not require a new hire. It is usually 10 to 15 hours per week for four to six months. If you do not have someone to assign, you can hire a compliance consultant to do it, which costs $5,000 to $15,000 but keeps the audit moving.

Gather evidence systematically, not at the last minute

The biggest reason SOC 2 audits run long is that companies wait until the auditor asks for evidence, then scramble to find it. If you are doing a Type II audit, you need six months of evidence that your controls actually ran. If you start gathering it in month five, you will not have it.

Start gathering evidence as soon as you have documented your controls. If your policy says you review user access quarterly, do the first review now and keep the documentation. If your policy says you test disaster recovery annually, schedule that test and document it. If your policy says you log all administrative actions, set up logging now and let it run for six months before the audit starts.

For controls that generate automatic evidence (logs, system records, configuration files), export them monthly and store them in a central location. For manual controls (reviews, approvals, training), create a straightforward form or checklist and fill it out every time you perform the control. This takes 30 minutes per month and saves you weeks during the audit.

Plan for the audit fieldwork phase

Once you have submitted all your documentation, the auditor schedules fieldwork — usually two to four weeks of on-site or remote review. During this time, the auditor will interview your staff, review your evidence, test your controls, and ask follow-up questions. You need to have people available to answer questions and provide additional documentation if the auditor finds gaps.

The auditor will likely find issues: a control that was not performed in one month, a policy that was not followed exactly as written, or evidence that is incomplete. This is normal. You will have a chance to explain or fix it. If the issue is minor, the auditor notes it and moves on. If it is significant, you may need to remediate it before the audit concludes.

Plan for your team to spend 20 to 40 hours during fieldwork answering questions and pulling additional documents. Have your audit owner coordinate this and keep a list of outstanding items so nothing falls through the cracks.

Budget for the full cost, including hidden expenses

The audit fee is only part of the cost. You also need to budget for internal labor (your audit owner, security team, and other staff time), any controls you need to build or fix, and possibly a compliance consultant if you do not have the informed in-house.

Cost CategoryTypical RangeWhat It Covers
Audit firm fee$15,000–$100,000Scoping, fieldwork, report
Internal labor$10,000–$40,000Audit owner, staff time, documentation
Control implementation$5,000–$50,000Tools, engineering time, policy writing
Compliance consultant (optional)$5,000–$20,000Scoping, documentation, remediation

A small company with basic controls in place might spend $30,000 total. A larger company with no controls documented might spend $150,000 or more. Get a detailed estimate from your audit firm and add 20 percent for unexpected issues.

Frequently Asked Questions

How long does SOC 2 certification actually take?

Type I takes three to five months. Type II takes six to nine months because you must demonstrate that your controls worked consistently over at least six months. The timeline depends on how much documentation you already have and how quickly your team responds to the auditor's requests.

Do I need to hire a consultant to get SOC 2 certified?

No, but many companies do because it speeds up the process. A consultant can help you scope the audit, document controls, and gather evidence. If your team has security or compliance experience, you can do much of it yourself and hire a consultant only for specific gaps.

What happens if the auditor finds a control that is not working?

The auditor will note it as a finding. You then have the chance to fix it or explain why the risk is acceptable. Minor findings do not prevent you from getting the report, but significant ones may delay it until you remediate.

Can I use the same SOC 2 report for multiple clients?

Yes. The report is yours to share. Many clients ask for it, and you can give the same report to all of them. You do not need a separate audit for each client.

What is the difference between SOC 2 Type I and Type II?

Type I is a snapshot — the auditor reviews your controls at one point in time. Type II shows that your controls worked consistently over at least six months. Most enterprise clients require Type II because it proves your practices are sustainable, not just theoretical.