SOC 2 is the report most B2B customers ask for before they trust you with their data. Here's what it actually is, in plain English.
The short answer
SOC 2 is an independent attestation report, written by a licensed CPA firm, describing how well your controls protect customer data against the AICPA Trust Services Criteria. It's not a certificate you pass/fail — it's a report a prospect's security team reads.
The five Trust Services Criteria
- Security (always included) — protection against unauthorized access.
- Availability — the system is available for operation and use.
- Processing integrity — processing is complete, accurate and timely.
- Confidentiality — confidential information is protected.
- Privacy — personal information is handled per your notice.
You choose which criteria are in scope; almost everyone includes Security.
Type I vs Type II
A Type I report assesses your controls at a point in time; a Type II assesses how they operated over a period (usually 3–12 months). Most customers ultimately want Type II. Full comparison here.
Who needs it?
Any company that stores or processes customer data and sells to other businesses — especially SaaS. It's often the gate to closing enterprise deals in North America.
General explainer, not audit advice. SOC 2 reports are issued by a licensed CPA firm, not by Vallorix.