Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Compliance readiness

SOC 2 readiness: prepare for an independent CPA examination

Get your controls, evidence, and system description ready for a SOC 2 examination by an independent, licensed CPA firm that you select and engage directly.

Version as of

2017 Trust Services Criteria (With Revised Points of Focus – 2022)

Criteria issued in 2017; points of focus revised in 2022

As of 2026-09-26 the AICPA has not issued revised criteria. The 2022 revision changed the points of focus, not the criteria. SOC 2 examinations are performed under AICPA attestation standards AT-C 105 and AT-C 205.

Check the official SOC 2 source (external site)

What is SOC 2?

SOC 2 is an attestation report on a service organization's controls, issued by a licensed CPA firm after an examination and measured against the AICPA Trust Services Criteria. It isn't a certification.

In a SOC 2 examination, a licensed CPA firm gives an opinion on your description of your system and on whether your controls are suitably designed to meet the applicable criteria, which cover security, availability, processing integrity, confidentiality, and privacy. A Type 2 report adds an opinion on whether those controls operated effectively over a period.

Your management is responsible for the system, its controls, and the description of the system. The CPA firm examines them; it doesn't build them.

Type
Framework or voluntary standard
Current version, as of
2017 Trust Services Criteria (With Revised Points of Focus – 2022). Criteria issued in 2017; points of focus revised in 2022. Version source for SOC 2 (external site)

Who needs a SOC 2 report?

  • Service organizations whose customers ask for a SOC 2 report before they share data or sign a contract
  • SaaS and professional-services firms that host, process, or support systems holding customer data
  • Teams answering frequent customer security questionnaires that want an independent report to share
  • Organizations that want to understand the gap before they engage and pay a CPA firm

Which report type to plan for

A SOC 2 Type 1 report and a Type 2 report start from the same place: the CPA firm's opinion on your system description and on whether your controls are suitably designed to meet your service commitments and system requirements, based on the applicable Trust Services Criteria. A Type 2 report adds an opinion on whether those controls operated effectively, and it includes the service auditor's detailed description of its tests of controls and their results.

A Type 1 report speaks to a single date. A Type 2 report covers a period of time, so its tests show how controls worked in practice, including any exceptions. Which one you need usually depends on what your customers ask for, and the CPA firm you engage agrees the report date or period with you during scoping.

SOC 2 Type 1 and Type 2 reports compared (AICPA description criteria DC 200, paragraph .03 and footnote 5)
QuestionType 1 reportType 2 report
What the opinion coversThe system description and the suitability of control designThe system description, the suitability of control design, and the operating effectiveness of controls
Time frameAs of a specific dateThroughout a period of time
Tests of controls in the reportNot includedA detailed description of the service auditor's tests of controls and their results
Who issues itA licensed CPA firm acting as service auditorA licensed CPA firm acting as service auditor

Sources: AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)

The criteria your controls are measured against

The AICPA's 2017 Trust Services Criteria are organized into five categories: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 examination can report on one category or on several together.

Each criterion comes with points of focus that describe its important characteristics. The AICPA says using the criteria doesn't require assessing whether every point of focus is addressed, so they work as guidance rather than a checklist. The points of focus were revised in 2022; the criteria themselves date from 2017.

Every category builds on the common criteria, a shared set numbered CC1 through CC9. For security, the common criteria are the complete set. Availability, processing integrity, confidentiality, and privacy each add their own criteria on top of them: the A, PI, C, and P series. The common criteria cover:

  • CC1: control environment
  • CC2: information and communication
  • CC3: risk assessment
  • CC4: monitoring activities
  • CC5: control activities
  • CC6: logical and physical access controls
  • CC7: system operations
  • CC8: change management
  • CC9: risk mitigation, including risks from vendors and business partners

Source: AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)

SOC 1, SOC 2 and SOC 3: which report is which

The AICPA's System and Organization Controls suite includes three reports for service organizations, and they answer different questions. All three come from a CPA firm's examination under AICPA attestation standards.

  • SOC 1 reports on controls at a service organization that are relevant to its customers' internal control over financial reporting (AT-C section 320).
  • SOC 2 reports on controls relevant to security, availability, processing integrity, confidentiality, or privacy, measured against the Trust Services Criteria. It includes management's system description, and a Type 2 report also includes the service auditor's detailed tests of controls and results.
  • SOC 3 covers the same Trust Services Criteria categories and contains an opinion on the operating effectiveness of controls, but without the detailed description of tests and results. The AICPA describes it as a general use report that can be freely distributed.

Sources: AICPA: System and Organization Controls (SOC) suite of services; AICPA & CIMA: SOC 3, SOC for Service Organizations: Trust Services Criteria for General Use Report; AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)

What's inside a SOC 2 report

A SOC 2 report follows a predictable structure. The AICPA's illustrative report shows the main parts: the service auditor's report, management's assertion, the description of the system, and, in a Type 2 report, the tests of controls and their results.

The system description is management's document, prepared against the AICPA's 2018 description criteria (DC 200). The criteria ask it to cover:

  • The types of services provided
  • The principal service commitments and system requirements
  • The components of the system: infrastructure, software, people, procedures, and data
  • Identified system incidents that resulted from ineffective controls or caused a significant failure to meet commitments or requirements
  • The applicable Trust Services Criteria and the related controls
  • Complementary user entity controls: controls the service organization assumed its customers would operate
  • Subservice organizations, described with either the inclusive method or the carve-out method
  • Any criterion that isn't relevant to the system, and why
  • For a Type 2 report, significant changes to the system and controls during the period

Sources: AICPA & CIMA: Illustrative SOC 2 report with illustrative system description; AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022)

Preparing for the examination, in order

Readiness is the work you do before a CPA firm starts its examination. The same seven steps as the full checklist guide, in the order that saves rework:

  1. Decide between a Type 1 and a Type 2 report, and which services it covers
  2. Define the system boundary, including subservice organizations and complementary user entity controls
  3. Pick the Trust Services Criteria categories that match your customer commitments
  4. Assess gaps against the common criteria (CC1 to CC9) and any added categories
  5. Write and approve the policies your team will follow
  6. Collect evidence that each control operates, and rehearse the requests a CPA firm is likely to make
  7. Choose a licensed CPA firm and check its license and peer review

Sources: AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)

Formal assessment: who performs it, and on whose authority

Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.

Formal outcome
A SOC 2 Type 1 or Type 2 report: an attestation report, not a certification
Who performs it
A licensed CPA firm, performing the examination under AICPA attestation standards (AT-C 105 and AT-C 205). State accountancy laws generally reserve attest work, including SOC 2 examinations, for licensed CPAs practicing through a permitted CPA firm. No AICPA-issued or state-recognized individual SOC 2 credential authorizes anyone to issue a report.

Outside our services

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

What we do and don’t do

SOC 2 readiness — preparation for an examination performed by an independent licensed CPA firm.

What we do

  • Readiness assessment of your controls against the 2017 Trust Services Criteria (2022 points of focus)
  • Help deciding the system boundary, the criteria in scope, and whether a Type 1 or Type 2 report fits your customers
  • Control and policy recommendations for each gap; your management decides what to implement
  • Evidence-readiness reviews and mock walkthroughs of the evidence a CPA firm is likely to request
  • Help drafting your system description for management's review and approval
  • Neutral guidance on how to check a CPA firm's license and peer review

What we don’t do

  • Perform the SOC 2 examination, or issue a SOC 2 report, opinion, or attestation
  • Take part in the examination of controls we helped you prepare
  • Make control decisions or own your system description; your management keeps those responsibilities
  • Bundle an examination with our readiness work, or set or influence a CPA firm's fees
  • Promise a clean opinion or a date for your report

Independence

Under the AICPA Code of Professional Conduct, a CPA firm impairs its independence if it designs, implements, or maintains the controls it examines, prepares the system description, or decides which recommendations to implement (ET 1.295.030 and 1.295.145). No safeguard fixes that. The Code's relief for attestation engagements (ET 1.297.030) covers only services unrelated to what's examined, and readiness work always relates to it. Keeping readiness work separate from the examination avoids the conflict.

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

How advisory work and formal assessment stay separate

How readiness works

Every engagement begins with a written scope and proposal.

  1. Scope

    Confirm which services and systems are in scope, which Trust Services Criteria apply, and whether a Type 1 or Type 2 report fits what your customers ask for.

  2. Assess gaps

    Compare your current controls and evidence with the criteria and points of focus, and rate each gap by risk and effort.

  3. Plan remediation

    Agree on a prioritized plan. Your team decides on and implements the changes; we advise and review.

  4. Rehearse evidence

    Review evidence samples and walk through key controls, so your team knows what a CPA firm is likely to ask for.

  5. Hand off

    Prepare a readiness summary you can share with the CPA firm you select. That firm plans and performs its own examination.

Deliverables

  • Readiness report with each gap rated by risk and effort
  • Trust Services Criteria matrix mapped to your controls and evidence
  • Prioritized remediation plan
  • Policy and system-description recommendations for management's review
  • Evidence request list and walkthrough notes

What SOC 2 readiness costs

  • SOC 2 Readiness

    From $10,000

    Typical scoped range: $10,000 to $25,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Guides

Frequently asked questions

Is a SOC 2 report the same as a certification?

No. SOC 2 is an attestation report: a licensed CPA firm examines your system description and controls and expresses an opinion on them. In an April 2026 Journal of Accountancy podcast, an AICPA vice president said that SOC 2 is not a certification. There's also no AICPA-issued or state-recognized individual SOC 2 certification, and no individual credential authorizes anyone to issue a SOC 2 report.

What's the difference between a Type 1 and a Type 2 report?

A Type 1 report gives the CPA firm's opinion on your system description and on whether your controls are suitably designed to meet the applicable criteria. A Type 2 report adds an opinion on whether those controls operated effectively over a period. Your customers' requirements usually decide which one you need, and scoping is the time to confirm it.

Can our CPA firm do the readiness work too?

Only within limits. The AICPA Code lets a CPA firm give an examination client advice and recommendations if management makes every decision and a written understanding is in place before the work starts (ET 1.295.040). A firm that designs, implements, or maintains the controls it examines, or prepares the system description, impairs its independence, and no safeguard fixes that. Using a separate readiness firm keeps that question off the table.

How do we check a CPA firm before engaging it?

Confirm that the firm and the people who will sign the report are licensed, using the state board of accountancy or NASBA's CPAverify search. CPAverify doesn't include Hawaii or New Mexico, so check those boards directly. You can also look up the firm's peer review enrollment in the AICPA Peer Review Public File, or ask the firm for its latest peer review report.

Which version of the criteria applies?

As of 2026-09-26, the current criteria are the AICPA's 2017 Trust Services Criteria with revised points of focus from 2022, used with the 2018 SOC 2 Description Criteria (revised implementation guidance, 2022). The 2022 revision changed the points of focus, not the criteria. Check the AICPA's criteria page for any later revision before you plan the work.

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Primary sources

Talk to a practitioner about SOC 2 readiness

Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.

What happens next

  1. Tell us about your environment and the formal outcome you're working toward.
  2. Talk through scope, timing, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.