SOC 2 - TRUST SERVICES - AICPA

The report your American buyers read first.

Your first U.S. customer asks for your SOC 2 report. You don’t have one, so they politely suggest they’ll “revisit when you do.” Welcome to the American enterprise market - where SOC 2 is what ISO/IEC 27001:2022 is in Europe: the default trust mechanism procurement teams ask for before they ask anything else.

60-70%

Controls shared with ISO/IEC 27001:2022 Annex A

5

Trust Service Criteria - Security is mandatory

3-12mo

Type II observation period

2

Report types - Type I and Type II

1

THE FRAMEWORK

What SOC 2 actually is

An attestation report.
Not a certificate.
Not a checklist.

SOC 2 is not a checkbox - it is the gate. It is what ISO/IEC 27001:2022 is in Europe: the default trust mechanism American procurement teams ask for first.

Developed by the AICPA and governed by U.S. accounting standards, SOC 2 is used globally by anyone selling SaaS to American buyers. It reports against five Trust Service Criteria - Security, Availability, Processing Integrity, Confidentiality and Privacy - and you pick the ones that matter for your business, with Security always mandatory.

It comes in two flavours: Type I, a point-in-time snapshot of control design, and Type II, which proves operating effectiveness across a 3–12 month observation period - the only one serious enterprise buyers accept. Reports renew annually; technically it isn’t certification, but in practice every SaaS company treats it exactly like one.

2

THE FIT

Who actually needs this

SOC 2 stops being a “later” problem the moment one of these describes you.

01
You sell B2B SaaS to U.S. companies.

Especially mid-market and enterprise. No SOC 2 means no contract for a meaningful share of your potential market.

02
You’re entering U.S. fintech, healthcare or insurance.

These three sectors don’t even start the conversation without a SOC 2 Type II report on the table.

03
You’re raising capital from U.S. investors.

A surprising amount of due diligence asks “have they done their SOC 2 yet?” before it asks “what’s their ARR?”

04
You already have ISO/IEC 27001:2022 and want to maximise coverage.

60–70% of SOC 2 controls overlap with ISO/IEC 27001:2022’s Annex A - same evidence, different report.

If none of these describe you - wait. If even one does - yesterday was the best time to start.

3

THE PAYOFF

What you actually get from a report

We could write four paragraphs of marketing copy - instead:

I.

Unlock the U.S. enterprise market. This is the whole point. Without it, half your TAM is sealed off.

II.

End the “ISO/IEC 27001:2022 isn’t enough for us” objection. Many U.S. buyers won’t accept ISO/IEC 27001:2022 as a substitute. SOC 2 closes the conversation.

III.

Build trust faster with sophisticated buyers. A SOC 2 Type II report tells a more dynamic story than a static certificate - it covers months of actual operations.

IV.

Stack with ISO/IEC 27001:2022 - one audit, two outputs. Our “One Audit” approach means a single evidence pool, two reports, and a dramatically lower combined cost.

V.

Annual renewal = annual improvement. Continual improvement stops being a value statement and becomes a delivery schedule.

4

THE FIVE CRITERIA

The Trust Service Criteria are your menu, not your sentence

A SOC 2 report is scoped to the criteria you choose. Security is the mandatory Common Criteria every report shares; the other four are added based on the commitments you actually make to customers.

MANDATORY

Security
Scope & criteria selection

Protection of systems and data against unauthorised access, use, or modification - the baseline every SOC 2 engagement is built on.

Every SOC 2 report includes Security. The other four are added based on the promises you make to customers.

OPTIONAL

Availability

Systems are available for operation and use as committed or agreed - uptime, resilience and disaster recovery.

OPTIONAL

Processing Integrity

System processing is complete, valid, accurate, timely and authorised - the data does what it should, when it should.

OPTIONAL

Confidentiality

Information designated as confidential is protected throughout its lifecycle, as committed to customers and partners.

OPTIONAL

Privacy

Personal information is collected, used, retained, disclosed and disposed of in line with your stated commitments.

5

TYPE I & TYPE II

Two flavours - and only one closes enterprise deals

Both report on the same controls. The difference is whether they capture a single moment or a stretch of real operations.

Type I

WHAT BUYERS ACCEPT

A point-in-time snapshot - your controls are designed correctly as of a single specific date.

WHAT IT TESTS

Control design

PERIOD

A specific date

TRADE-OFF

Faster, cheaper

BUYER VIEW

A useful early signal

Type II

WHAT BUYERS ACCEPT

Operating effectiveness of your controls, observed across a 3–12 month window.

WHAT IT TESTS

Design + effectiveness

PERIOD

3 - 12 months

TRADE-OFF

Slower, pricier

BUYER VIEW

A serious candidate

6

THE ATTESTATION ROADMAP

From scope to report, in four moves

A transparent, digital-first workflow. Your client portal gives real-time visibility into status, evidence and findings at every stage.

01

DIGITAL

Scope & criteria selection

Choose which of the five Trust Service Criteria apply. Security is mandatory; you add Availability, Processing Integrity, Confidentiality or Privacy based on your actual business - not a template’s idea of one.

02

HYBRID / ONSITE

Readiness & gap assessment

We map the selected controls against your existing evidence - reusing your ISO/IEC 27001:2022 Annex A work where it overlaps - and close gaps before the observation window opens.

03

HYBRID / ONSITE

Type II observation period

Controls are tested for operating effectiveness across a 3–12 month window - the report that serious enterprise buyers actually accept, rather than a point-in-time snapshot.

04

OUTCOME

Attestation report

A licensed CPA firm issues your SOC 2 report. Annual renewal keeps it current - and in practice every SaaS company treats it exactly like a certification.

7

ONE AUDIT - TWO OUTPUTS

Stack it with ISO/IEC 27001 and assemble the evidence once

Roughly 60–70% of SOC 2 controls overlap with ISO/IEC 27001:2022’s Annex A - the same evidence, presented as a different report. Our “One Audit” approach runs them together from a single evidence pool, producing two formal outputs at a dramatically lower combined cost.

And SOC 2 is rarely the last step. ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001:2023 and BSI C5 each assume an ISO/IEC 27001:2022-class foundation already exists. Build the ISMS once and every subsequent report costs less, not more - one coordinator across the whole engagement.

STANDARDS ONE EVIDENCE POOL CAN FEED

ISO/IEC 27001:2022

ISO/IEC 27017

ISO/IEC 27018

ISO/IEC 42001:2023

BSI C5

ISO 22301

GET IN TOUCH

Start your application process
now

Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.

8

FAQs

Clear answers, the same way we run an audit

Is SOC 2 a certificate?

We already hold ISO/IEC 27001:2022 - does that help?

Which Trust Service Criteria should we include?

Type I or Type II - which do we need?

How can Proks issue a SOC 2 report if it must come from a CPA firm?

How long does a SOC 2 report stay valid?