Attestation report
SOC 2: Trust Services Criteria, Type I vs Type II, and evidence
In short
SOC 2 is an attestation report developed by the AICPA in which an independent CPA gives an opinion on how well a service organization’s controls meet the Trust Services Criteria. Unlike ISO 27001 it is not a certification — it is a report, most often requested by US customers as assurance that a vendor handles their data securely.
Last reviewed: August 2026
Who it is for
SOC 2 is aimed at service organizations — especially SaaS and cloud providers — that store or process customer data. It is the de facto trust signal in US B2B sales, frequently required before a security review will pass. Companies selling into both the US and Europe often pursue SOC 2 and ISO 27001 together.
The Trust Services Criteria
Security is always in scope; you choose which of the other four categories to include based on what you commit to customers.
- Security (the mandatory “common criteria”)
- Availability
- Processing integrity
- Confidentiality
- Privacy
Type I vs Type II
| SOC 2 Type I | SOC 2 Type II |
|---|---|
| Controls at a single point in time | Controls operating over a period (typically 3–12 months) |
| Design of controls | Design and operating effectiveness |
| Faster to obtain | Higher assurance, what customers usually want |
Typical compliance challenges
- Sustaining evidence across the whole Type II observation window, not a snapshot
- Collecting evidence from identity, cloud, code and HR systems continuously
- Keeping policies and controls aligned as the company changes
- Avoiding duplicate work when SOC 2 overlaps ISO 27001
What can reasonably be automated
- Continuous control monitoring across the observation period
- Automated, time-stamped evidence instead of manual screenshots
- Mapping SOC 2 criteria to ISO 27001 controls to reuse evidence
- Findings and remediation ownership when a control drifts
Evidence auditors expect
- System description and control matrix mapped to the criteria
- Access reviews, change-management records and monitoring logs
- Incident and vulnerability-management records
- Vendor / subservice-organization assessments
- HR evidence such as onboarding, offboarding and security training
How Isodora supports SOC 2
Isodora keeps the controls behind a SOC 2 report operating and evidenced across the whole observation window.
Continuous evidence
Automated, time-stamped evidence across the Type II period — not a pre-audit scramble.
Criteria mapping
Map the Trust Services Criteria to ISO 27001 controls so evidence is reused across both.
Findings & ownership
When a control drifts, an owned finding opens automatically so it is fixed before the audit window closes.
Trust Center
A public, always-current page that shows customers and procurement your security posture.
A SOC 2 report is issued only by an independent CPA firm after its own examination. Isodora helps you prepare and maintain the controls and evidence; it does not issue the report.
Frequently asked questions
- Is SOC 2 a certification?
- No. SOC 2 is an attestation report in which a licensed CPA firm gives an opinion on your controls against the Trust Services Criteria. There is no certificate — customers read the report itself.
- What is the difference between SOC 2 Type I and Type II?
- Type I assesses whether controls are suitably designed at a point in time. Type II also tests whether they operated effectively over a period, usually three to twelve months. Customers typically want a Type II.
- How does SOC 2 compare to ISO 27001?
- SOC 2 is a US attestation report; ISO 27001 is an internationally recognized certification of a management system. They share a large amount of underlying evidence, so many companies do both and reuse controls to satisfy each.
- How long does a SOC 2 Type II take?
- After controls are in place, a Type II covers an observation window that is commonly three to twelve months, followed by the auditor’s examination and report. Continuous evidence collection shortens the practical effort considerably.