A customer has asked for your SOC 2. What they want is a report an accounting firm writes about how a company runs the systems that hold their data, addressed to named readers rather than published. Nothing else carrying those three letters is in play here. Not SOC 1, which covers the controls that matter to somebody else’s financial statements. Not SOC 3, the shorter version anyone is allowed to read. Not the accounting sense of the word, and not the staffed monitoring room some large companies run overnight.
A SOC 2 report is an examination performed by a licensed CPA firm, not a certificate anybody issues. Four of the seven company pages ranking for this question on 3 September 2026 state in their own words that no law requires one. What makes it necessary is the sentence your customer wrote, so start by reading that sentence.
The awkward part is that the question is not really about SOC 2. It is about one customer, one sentence, and what you can put in front of them before a deadline. The pages ranking for it answer a different question, and the reason they do is written down in the accounting profession’s own magazine.
Everything below that says what a SOC 2 report is, who is allowed to write one and how long one takes was read on 3 September 2026 from the profession’s own magazine and from the published timeline pages of two licensed CPA firms, and each source is named beside the fact it carries, with the search results counted the same day and dated because a result set stops being true quickly. No examination was bought, commissioned, observed or signed to write this page, no auditor and no vendor was asked for anything, and nothing here is legal advice or a judgement about whether your own controls would pass.
Who is actually asking, and what they wrote down
The request turns up in one of three shapes: a line in an email from the person who wants to buy, a row on a form from their vendor risk team, or a clause in a draft agreement. The shape tells you who you are talking to and how much room there is to answer with anything else.
An email is the easy one, because a person wrote it and that person can be asked what they mean. Buyers use the phrase loosely. Some want the document itself, some want to know one is coming, and some are repeating a word their own security reviewer used. One reply settles it: ask whether they need the report in hand before signature, or a date by which it will exist, and which type they mean. A Type 1 report examines whether the controls were designed properly at one point in time; a Type 2 report examines whether they operated across a stated period, which is why it takes longer.
A row on a form is a different animal, because the form is scored by a process rather than read by a person. A blank scores worse than an honest no, and a yes you cannot support becomes a warranty if the completed form ends up attached to the agreement. The alternative to holding a report is answering the same questions one customer at a time, on the spreadsheet each of them sends, and that job has a shape worth understanding before the first one arrives.
A clause in a draft agreement is the one worth slowing down for. Contract language names a report type and a date, sometimes an annual cadence, occasionally a right to receive the report every year for the life of the deal. That is a commitment about the future, and it is far cheaper to negotiate before signature than to discover afterwards.
Now the part that makes the reading so unsatisfying. On 3 September 2026 the seven company pages on page one for this question answered “who needs SOC 2” the same way: by industry list. Scrut runs six numbered industry sections, from technology and SaaS through to managed service providers. Drata runs eight, adding data centres and government contractors. Nobody sends a purchase requirement to an industry. The request in your inbox came from one company with one procurement policy, and the industry the two of you are in did not write it.
A customer who asks for this rarely asks for only this, and the rest of the list that tends to arrive with it is worth reading in one piece.
What the report actually is, in the words of the profession that writes it
A SOC 2 report is the output of an examination, performed by a CPA firm, about controls a company operates over its customers’ data. The subject matters it can cover are named and there are five of them. Nobody awards it, nobody renews it, and no register exists to look a company up in.
The clearest published description of what those reports cover comes from the accounting profession itself. The Journal of Accountancy’s February 2026 report on the SOC market, by Andrew Kenney, dated 1 February 2026 and read on 3 September 2026, states that “SOC 2 reports can address controls relevant to security, availability, or processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information these systems process”. Those are the five subject areas your customer’s reviewer will look for on the front of the document.
Who is allowed to produce one is narrower than most founders expect. A-LIGN, a licensed CPA firm that publishes its own SOC 2 timeline at a-lign.com/articles/blog-how-long-does-it-take-to-complete-soc-2-audit, writes on that page that “SOC 2 audits are regulated by the AICPA and reports can only be generated by an external auditor from a licensed CPA firm …”. Read on 3 September 2026. That single sentence rules out a large part of what a founder finds while searching, because most of the companies ranking for this subject are software vendors rather than accounting firms.
The word almost everyone uses for the outcome is the wrong one, and the profession says so in print. The same February article describes tool vendors promising compliance, “a term never used in SOC 2 examinations”, in weeks or hours. Across every source read for this page the profession’s own wording describes an examination and a report, and no certificate, accreditation body or certification number appears anywhere in them.
That matters for what you write, not just for what you know. On the seven company pages ranking for this question, read whole on 3 September 2026, the exact phrases “SOC 2 certification” and “SOC 2 certified” appear zero times. The word stem “certif” appears in the readable text of five of the seven, and in the browser tab title of one of them. The pages are careful in the sentence and loose in the furniture, which is how the word ends up in a founder’s email to a customer.
None of this is about the platform you built on. A vendor’s own report covers the vendor’s systems, and what a platform’s own report settles for the app you built on it is a separate reading with a separate answer.
Why every page you have read on this says the same thing
The result set for this question is unusually one-sided, and the composition is checkable. Eight organic results on 3 September 2026: one forum thread and seven company pages, five published by companies selling compliance or governance software and two by security vendors. Zero CPA firms. Zero pages from the body that publishes the standard.
The same count came back on “is soc 2 mandatory”, read the same day: one forum thread, seven company pages, no accounting firm anywhere on the page. Change the question to how long a SOC 2 takes and the composition flips, with two CPA firms ranking on the first page. The profession is reachable on the mechanical question and absent on the decision.
The seven pages behind those counts are paloaltonetworks.com/cyberpedia/soc-2, zengrc.com/blog/6-reasons-why-you-need-soc-2-compliance/, oneleet.com/blog/shopping-guide-when-do-you-actually-need-soc-2-compliance, vanta.com/collection/soc-2/why-is-soc-2-important, scrut.io/hub/soc-2/who-needs-soc-2, drata.com/learn/soc-2/overview and fortinet.com/resources/cyberglossary/soc-2-compliance. Each was read whole on 3 September 2026 by an ordinary request and by a browser-imitating one. Six returned the same text to both. The Drata page refused the ordinary request and answered the browser-imitating one, which is recorded here as a split read rather than as a refusal, and none of the seven is linked from this page. The eighth result, and the one that ranked first, is a thread on r/startups that returned no readable text to either shape on that date, so no sentence from it appears anywhere here and its position is all it is cited for.
There is a published explanation for that, from a person on the committee that owns this subject. The February article attributes it to Sean Linton, CPA/CITP, an audit partner at EisnerAmper LLP who chairs the AICPA’s SOC 2 Working Group: thanks to heavy investment in search-engine optimisation, “these companies now dominate online search results for SOC 2 services”. A founder reading page one is reading a market, and the market has an interest in the answer being yes.
The same article names the structural reason those companies cannot answer the whole question anyway. Because most of the new tool providers are not CPA firms, they cannot attest that the controls in place are effective and appropriate. Some have cultivated networks of accounting firms to complete the examinations, and some refer clients to firms that can perform them. The software is real and useful, and the signature at the end belongs to somebody else.
On the actual question the reader typed, the ranked pages are more honest than their headlines suggest. Four of them settle it in their own words, all read on 3 September 2026. ZenGRC, under its own heading asking whether SOC 2 is required by law: “No. SOC 2 is not mandatory in a legal sense, and certification isn’t required by law.” Scrut, in its FAQ: “No. SOC 2 is not mandated by law or regulation. However, it’s often contractually required by enterprise clients or business partners, especially if your services involve handling sensitive data.” Drata, in its key takeaways: “SOC 2 is a voluntary AICPA auditing framework for organizations that store, process, or transmit customer data. It’s not legally required, but it’s effectively table stakes for winning enterprise B2B contracts.” Vanta: “While a SOC 2 is not required by law … customers often need to see your SOC 2 report before they agree to do business with you.”
Four companies with every commercial reason to say the opposite all print the same thing. What decides this for you sits in a contract rather than in a statute, which is why the sentence your customer wrote deserves more attention than anything on page one.
What a report is actually for once you have one
A SOC 2 report exists to stop the same conversation happening with every new customer. One document, produced by an outside firm, answers a question that would otherwise arrive one buyer at a time with a different spreadsheet attached each time.
A-LIGN puts the business case plainly on its own timeline page, read 3 September 2026: a SOC 2 report is a third-party validation used in due diligence with multiple prospects and customers, “replacing the need to undergo a custom cybersecurity audit with each new customer”. That is the honest reason a small supplier would want one. It turns a job that repeats with every deal into one that repeats on a cycle, and it does that only if the buyers on the other side accept it. Cherry Bekaert’s timeline page, read the same day, says that once established, most organisations undergo annual examinations.
Acceptance is the part nobody selling you the report controls. In the February article, Jeff Cook, CPA, principal at IT-audit firm Fortreum Associates LLC and a member of the SOC 2 Working Group, is quoted on what happens when a buyer rejects one: “it’s not worth the paper it’s on”. A report that a customer’s reviewer sends back has cost you the money and the months and closed nothing.
So the useful version of “why is SOC 2 important” is narrower than the reason lists on page one. A report matters to the extent that the buyers you actually sell to will take it instead of asking their own questions, and for a first enterprise customer that is often one buyer.
How long it takes, and what the AICPA does and does not set
Months. On the evidence of the one CPA firm page read here that addresses it directly, the floor everyone quotes is convention rather than a rule, and the shortest testing period that firm says it sees in practice is three months. The phases either side of that add up to a first report measured in quarters.
Cherry Bekaert, a CPA firm that publishes SOC reporting services, states on its own timeline page at cbh.com/insights/articles/soc-2-report-examination-timeline-tips/ that “although the AICPA does not specify a minimum allowable audit period for a SOC 2 Type 2 examination, the shortest testing period typically seen in practice is three months”. Published 3 June 2025, read 3 September 2026.
Read that sentence twice, because it settles a question every timeline page on page one leaves open. The body that publishes the standard sets no floor, and the floor you keep reading about comes from what firms see in practice.
The absence is checkable at the source. On 3 September 2026 the SOC suite of services landing page the AICPA publishes was read whole and raw, including its embedded navigation, by an ordinary request and by a browser-imitating one. In its readable text and in its navigation it publishes no duration for an examination and no statement that any organisation is required to have one. The word month does not occur on the page at all, and the few occurrences of week, year and day sit inside the page’s own data payload, in a site banner about order emails, in the title and address of an unrelated news item and in a membership blurb. That is one page on one date, not the whole of what the body publishes, and it is the page a founder lands on first.
What a founder needs instead is a phase breakdown, and two CPA firms publish theirs. Cherry Bekaert’s, from the same page and the same read date:
| Phase, as Cherry Bekaert names it | What happens in it | The range Cherry Bekaert publishes |
|---|---|---|
| Phase I, Readiness Assessment | Controls are identified and mapped to the criteria, and the gaps are written down | 1 to 2 months |
| Phase II, Policy and Remediation or Control Implementation | The gaps identified in Phase I get closed, which is where the source’s own examples, a ticketing system or a security information and event management system, get built | 1 to 6 months, depending on maturity level |
| Phase III, Audit Fieldwork | The auditor tests, either at one date or across a period that has elapsed | 2 to 12 months, depending on reports used |
| Phase IV, Audit Wrap Up and Report Issuance | Review, quality control and the report itself | 1 month |
Add the two ends and a first report is a project measured in quarters. The firm’s own framing of why the total moves so much is the report type: the amount of time needed varies drastically between the two, because of the level of effort each one requires. Which of the two report types a customer wrote down changes what can be finished this quarter and what cannot.
Two weeks is the number the market advertises, and the profession answers it directly. A-LIGN’s page states that “although some organizations claim they can complete the SOC 2 audit process in as little as two weeks, experienced CPAs consistently note that this timeframe is unrealistic for a thorough, high-quality assessment”, and the same firm writes on the same page that a proper SOC 2 audit takes at least eight weeks to complete. Both read 3 September 2026, both that firm’s own published position.
The smaller numbers inside the process are worth having when a customer asks you for a date. A-LIGN gives its readiness phase as “Estimated timeline: varies (often several weeks)”, its audit window as two to six weeks, and its report issuance as three weeks, adding that “you’ll receive a draft report within three weeks of completing the fieldwork, sometimes earlier depending on deadlines and the complexity of the scope”.
What the whole thing costs is its own question, answered from the figures auditors and compliance platforms publish rather than from anything here. What the examination will actually look at inside a small team’s app, and which parts of that are code rather than paperwork, is its own subject again.
Why you cannot just download a real SOC 2 report to read
A finished SOC 2 report is a restricted-use document, written for readers who know the system, which is why a real one is normally requested from the company rather than found on the open web. The report your customer wants from you will be handed over the same way, under whatever distribution process the issuing firm uses.
The February article states that SOC 2 reports go to specified parties “with sufficient knowledge and understanding of the service organization’s system and the nature of services it provides”. That intended-use restriction is part of the document’s design; how each issuer distributes copies is its own process.
That reframes the search a founder usually runs at this point. A sample report is the one artifact in this subject that is deliberately not circulated. What you can legitimately read is a report you are entitled to receive, usually one from a supplier of yours, requested in writing.
The same mechanism explains what your customer is asking you for. They are not asking you to publish anything. They are asking to be added to the list of readers of a document that will describe your company by name and say what the auditor found. That is a different kind of thing from a badge on a pricing page, and worth knowing before you agree to produce one every year for the life of a contract.
What the profession says to ask before buying one
Four questions, published by the accounting profession for the person buying the report rather than for the firm selling it. The February article prints them as advice to clients seeking a SOC 2 report, and no page ranking on this question publishes a buyer’s checklist pointed at the seller.
- “Vet the CPA firm that will perform the SOC 2 attestation, including its size, capacity, and client references.”
- “Evaluate the firm’s qualifications, experience, and peer review results.”
- “Ask about the scope of the examination, the sampling procedures the CPA will use, and how the firm maintains its independence.”
- “Assess the offering. Is it unrealistically fast, easy, or cheap? …”
The reason the last one is on the list is described in the same article by Terry O’Brien, CPA/CITP, a director at Schellman and a member of the AICPA’s SOC 2 Working Group, talking about reports that come out of a template: “You just know it’s a template. You can compare any five of their reports, and they’re all exactly the same, with a different client logo on it.” A buyer who reads carefully can see it, which is the risk in buying the fastest report available.
One item there is genuinely awkward for a small supplier: peer review results and independence arrangements are not things a founder is used to asking about. Ask anyway. The question costs one sentence and the answer tells you what kind of firm you are dealing with.
The profession is also working on this from its own side. The same article reports that the AICPA is exploring a SOC Quality Center, which could serve as a badge of quality for participating firms. Exploring, as of that article’s publication on 1 February 2026, so it is not something to look for when choosing a firm today.
If the request in your inbox asked for a test of the running application rather than a report about your company, that is a different purchase entirely, and which kind of test a request will actually accept is decided on its own page, as is the broader question of which of a scan, a code review and a test you are being asked for.
The next move belongs to the person who asked
Nothing on this page tells you whether to buy a SOC 2 report, because that answer lives inside your customer’s procurement policy and not inside the standard. What this page can do is turn one vague request into four answerable questions, all of them addressed to them rather than to you.
Which document do they actually need, and does the contract name a type. When do they need it, and what happens on that date if it does not exist. Would they accept something else in the meantime, in writing, with a date attached. And is this requirement theirs, or inherited from a customer of theirs who will eventually read the report.
Ask those four before you talk to a firm. Each one is cheap to ask and expensive to guess at, and the answers decide whether anything in the table above needs to start this month at all.
Common questions about being asked for SOC 2
Is SOC 2 required by law?
No source read for this page states that any law requires it. Four of the seven company pages ranking for this question on 3 September 2026 say so in their own words, including ZenGRC (“SOC 2 is not mandatory in a legal sense”) and Scrut (“SOC 2 is not mandated by law or regulation”), and both add that customers and contracts frequently require it anyway. Whether a specific contract, regulator or sector rule applies to your company is a question for a lawyer who has read your agreements.
Is there such a thing as being SOC 2 certified?
Not as a status anybody issues. What exists is an examination performed by a CPA firm and a report signed at the end of it. The Journal of Accountancy’s February 2026 article describes tool vendors promising compliance, “a term never used in SOC 2 examinations”. If your website or your sales deck says certified, that wording came from a marketing page rather than from the profession that produces the document.
Is SOC 2 the same as SOC 1 or SOC 3?
No. The same February 2026 article states that “SOC 1 reports evaluate the service organization’s internal controls that are likely relevant to user entities’ internal controls over financial reporting”, which is a different subject from the one your software customer is asking about. SOC 3 is a shorter general use report. When a business customer asks a software supplier for “SOC 2” they mean the second of the three, and if their form says SOC 1 it is worth asking whether they meant it.
Who is allowed to perform a SOC 2 examination?
A licensed CPA firm. A-LIGN’s own page states that “SOC 2 audits are regulated by the AICPA and reports can only be generated by an external auditor from a licensed CPA firm …”, read 3 September 2026. The compliance platforms that dominate the search results here are software companies: the same article notes that because most of the new tool providers are not CPA firms, they cannot attest that controls are effective and appropriate.
Why can I not find a real SOC 2 report to read?
Because the finished report is a restricted-use document. The February 2026 article describes SOC 2 reports as going to specified parties “with sufficient knowledge and understanding of the service organization’s system and the nature of services it provides”. A real report is requested from a company you do business with, usually under an agreement, rather than downloaded. What circulates publicly under names like sample report is somebody’s illustration of the format.
Can a two-person company get a SOC 2 report?
Nothing in the two CPA firms’ published timelines makes company size a condition. Read whole on 3 September 2026, neither A-LIGN’s page nor Cherry Bekaert’s names a minimum company size, a headcount or a required team anywhere in its text or navigation. Cherry Bekaert mentions the size of an organisation only as one of the factors that changes how much resourcing a phase needs. What both describe instead is work to be done, and on a two-person company both jobs land on the same two people.
Does a SOC 2 report examine the code inside my app?
Not in the way founders assume. An examination looks at controls a company says it operates, tests whether they were designed and, for the longer report type, whether they ran across a stated period. Nothing in it is a judgement on how the code reads, and the report describes a boundary drawn around a system rather than a codebase.
Which of those controls turn out to be changes inside an application nobody has read end to end, rather than documents somebody writes, is a separate question with a page of its own.
What can I do while the examination has not happened yet?
Answer the questions the customer actually has, in writing, with a date against every line that is not true today. A dated statement of where things stand is a normal supplier answer, and buyers see them constantly.
That reply usually arrives as a form to fill in rather than a blank page, and the shape of that job, row by row, is worked through in full elsewhere on this site.
If you have a working app built with these tools and need it ready for real customers, this is what we do.
Built it with AI. Now it has to hold up for real customers.
The Production Hardening Sprint takes the app you already have and builds the production foundation underneath it. Authentication and access rules, payments that stay consistent, error handling, monitoring, backups, automated tests and a documented handover. Our engineers work inside your existing codebase for ten working days. All 123 deliverables are included, and you get the evidence for each one.
See the Production Hardening Sprint →
$2,500 fixed price · 10 working days · One codebase