Guide · SOC 2

What is SOC 2?

SOC 2 is the report most B2B customers ask for before they trust you with their data. Here's what it actually is, in plain English.

The short answer

SOC 2 is an independent attestation report, written by a licensed CPA firm, describing how well your controls protect customer data against the AICPA Trust Services Criteria. It's not a certificate you pass/fail — it's a report a prospect's security team reads.

The five Trust Services Criteria

  • Security (always included) — protection against unauthorized access.
  • Availability — the system is available for operation and use.
  • Processing integrity — processing is complete, accurate and timely.
  • Confidentiality — confidential information is protected.
  • Privacy — personal information is handled per your notice.

You choose which criteria are in scope; almost everyone includes Security.

Type I vs Type II

A Type I report assesses your controls at a point in time; a Type II assesses how they operated over a period (usually 3–12 months). Most customers ultimately want Type II. Full comparison here.

Who needs it?

Any company that stores or processes customer data and sells to other businesses — especially SaaS. It's often the gate to closing enterprise deals in North America.

How you get oneImplement the controls, collect evidence continuously, remediate gaps, then a CPA firm issues the report. A platform that automates evidence turns this from a months-long scramble into a background process.

General explainer, not audit advice. SOC 2 reports are issued by a licensed CPA firm, not by Vallorix.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect