Shieldra
SOC 2 Framework Guide
SOC 2 is an AICPA attestation framework for service organizations. An independent CPA firm evaluates whether the controls protecting customer data are suitably designed and, for Type II, whether they operated effectively over a period of time.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- SOC 2 is an attestation, not a certification — the deliverable is a report signed by a CPA firm, not a certificate.
- Security is the only mandatory Trust Services Category; the other four are included based on the commitments you make to customers.
- Type I evaluates control design at a point in time; Type II evaluates operating effectiveness over 3–12 months and is what enterprise buyers usually mean.
- The Common Criteria (CC1–CC9) are the backbone — every SOC 2 report covers them.
- Most findings come from missing evidence rather than missing controls.
What SOC 2 is — and is not
SOC 2 is a reporting framework published by the AICPA for service organizations that hold or process customer data. An independent CPA firm examines your controls against the Trust Services Criteria and issues a report containing their opinion, your management assertion, a system description, and the detail of what was tested.
It is not a certification, and no one can "be SOC 2 certified". There is no pass mark and no badge — a buyer reads the report, including any exceptions the auditor noted, and decides whether they are comfortable. That is also why the report has a date range: it describes a specific window, and a report from two years ago tells a customer very little.
Trust Services Categories
- Security (required) — protection against unauthorized access, disclosure, and damage
- Availability — the system is available for operation and use as committed
- Processing Integrity — processing is complete, valid, accurate, timely, and authorized
- Confidentiality — information designated confidential is protected as committed
- Privacy — personal information is collected, used, retained, and disclosed in line with your notice
Common Criteria
- CC1 Control Environment
- CC2 Communication and Information
- CC3 Risk Assessment
- CC4 Monitoring Activities
- CC5 Control Activities
- CC6 Logical and Physical Access Controls
- CC7 System Operations
- CC8 Change Management
- CC9 Risk Mitigation
Type I vs Type II
A Type I report assesses whether controls are suitably designed as of a single date. It is faster and cheaper, and it can unblock a deal while you accumulate history — but it says nothing about whether the controls actually ran.
A Type II report assesses whether those controls operated effectively across an observation window, typically 3 to 12 months. This is what most enterprise buyers mean when they ask for SOC 2, because design without operation is not much assurance. If you have time, going straight to Type II avoids paying for two examinations.
Where SOC 2 audits actually go wrong
The controls are rarely the problem. The problem is proving they ran. Auditors sample the observation period and ask for artefacts, and a control nobody can evidence for March is treated as a control that did not operate in March.
- Access reviews that were discussed but never documented or signed off
- Changes deployed without a linked ticket or a recorded approver
- A vendor list that exists but has no risk ratings or evidence of periodic review
- Alerting configured but no record that anyone triaged the alerts
- An incident response plan that has never been tested, or incidents with no closure documentation
- Offboarding that removed the account but left no timestamped record
Audit evidence
- Management assertion and system description
- Control matrix mapping controls to criteria
- Policies, procedures, and access reviews
- Infrastructure, logging, and monitoring evidence
- Vendor risk evidence
- Change management records
- Incident documentation
- Type I or Type II testing support
How to maintain SOC 2 continuously
A SOC 2 report covers a window, so the program has to run continuously rather than in a pre-audit sprint. In practice that means each recurring control has a named owner, a schedule, and a place its evidence lands automatically — quarterly access reviews, vendor reviews on renewal, annual policy re-acknowledgement, incident post-mortems filed on closure.
Teams that treat SOC 2 as an annual project pay for it twice: once in the scramble, and again in the findings that scramble produces. Shieldra keeps evidence attached to the control it proves and prompts the owner before it goes stale, which is what makes the second year cheaper than the first. SOC 2 is included from the Premium plan at $249/month.
SOC 2 alongside HIPAA
Healthcare SaaS teams usually need both — HIPAA because the law requires it when handling PHI, SOC 2 because customers require it before signing. Roughly 60–70% of the underlying technical controls overlap, including access control, encryption, logging, change management, vendor management, and incident response.
Mapping the two frameworks to shared evidence rather than running parallel programs is the single biggest efficiency available to a team facing both.
Frequently asked questions
What is SOC 2?
SOC 2 is an AICPA attestation framework for service organizations. An independent CPA firm evaluates whether a company controls protecting customer data are suitably designed (Type I) and operating effectively over a period of time (Type II), against the Trust Services Criteria.
What is the difference between SOC 2 Type I and Type II?
A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report assesses whether those controls operated effectively over an observation window, typically 3–12 months, and is what most enterprise buyers expect.
What are the SOC 2 Trust Services Criteria?
The five Trust Services Categories are Security (required), Availability, Processing Integrity, Confidentiality, and Privacy. Security is always in scope; the others are included based on the commitments a service organization makes to its customers.
Can a company be "SOC 2 certified"?
No. SOC 2 is an attestation, not a certification. An independent CPA firm issues a report containing their opinion, your management assertion, a system description, and the testing detail — including any exceptions. There is no certificate, no pass mark, and no certifying body.
What are the SOC 2 Common Criteria?
The Common Criteria, CC1 through CC9, are the control areas every SOC 2 report covers: control environment, communication and information, risk assessment, monitoring activities, control activities, logical and physical access controls, system operations, change management, and risk mitigation.
How do you maintain SOC 2 compliance continuously?
Give every recurring control a named owner, a schedule, and an automatic place for its evidence to land — quarterly access reviews, vendor reviews at renewal, annual policy re-acknowledgement, and incident post-mortems filed on closure. Because a Type II report covers a window rather than a date, evidence collected continuously is the only kind that survives sampling.
How long does a SOC 2 observation period last?
Type II observation windows typically run from 3 to 12 months. Shorter windows get a report sooner; longer windows carry more weight with enterprise buyers. Type I has no observation period because it assesses control design as of a single date.