HomeBlog › What Is SOC 2? A Plain-Language Guide for IT and SaaS Companies

What Is SOC 2? A Plain-Language Guide for IT and SaaS Companies

Published 2026-07-15 · 6 min read · BALTUM

If you sell software or IT services to customers in the United States or Western Europe, sooner or later someone will ask: "Do you have SOC 2?" This article explains what SOC 2 is, what a SOC 2 report actually contains, who issues it, and why it matters for a Ukrainian IT or SaaS company.

SOC 2 is a report, not a certificate

People often say "SOC 2 certification" or "SOC 2 certificate". Strictly speaking, that is not accurate. SOC 2 (System and Organization Controls 2) is an attestation report prepared by an independent, licensed CPA (Certified Public Accountant) firm in the United States under the standards of the AICPA, the American Institute of Certified Public Accountants.

The difference matters. A certificate, such as ISO 27001, confirms conformity to a standard and has an expiry date. A SOC 2 report is the auditor's professional opinion on whether a company's security controls are suitably designed (and, for Type 2, whether they operated effectively) over a defined period. There is no public register of "SOC 2 certified companies": the report is shared directly with customers and partners, usually under an NDA.

What a SOC 2 report attests to

The report evaluates the company's system of controls against the Trust Services Criteria (TSC). There are five:

  • Security — the mandatory criterion; every SOC 2 includes it. Protection against unauthorised access, access management, monitoring, incident response.
  • Availability — the system is available as committed to customers (SLAs, redundancy, disaster recovery).
  • Processing Integrity — processing is complete, accurate, timely and authorised.
  • Confidentiality — confidential information is protected throughout its life cycle.
  • Privacy — personal data is collected, used, retained and disposed of in line with the privacy notice and commitments.

The company chooses which criteria to include in scope. Most SaaS companies start with Security and often add Availability and Confidentiality.

What is inside the report

A typical SOC 2 report has four sections:

  1. Independent service auditor's opinion — the CPA firm's formal conclusion.
  2. Management's assertion — the company's statement that the system description is fair and the controls are suitably designed.
  3. System description — infrastructure, software, people, procedures, data, system boundaries and subservice organisations.
  4. Controls and test results — for each criterion: which controls exist, how the auditor tested them and which exceptions were found.

Section four is what your customers' security teams read most closely: it shows whether there were exceptions and how material they are.

Type 1 and Type 2: the difference

There are two report types. SOC 2 Type 1 evaluates the design of controls at a single point in time: do the right policies and mechanisms exist and are they capable of meeting the criteria? SOC 2 Type 2 additionally tests whether those controls actually operated over an observation period, typically 3 to 12 months.

Type 1Type 2
What is assessedDesign of controlsDesign and operating effectiveness
PeriodA single date3–12 months
Customer confidenceBaselineHigh
Typical goalClose a contractual requirement quicklyOngoing work with enterprise customers

For a full comparison see SOC 2 Type 1 vs Type 2.

Who needs SOC 2

SOC 2 is not required by law. In practice, however, it has become the market standard for any company that processes data belonging to US customers. SOC 2 is most often needed by:

  • SaaS products selling to corporate customers — the request appears as early as the security questionnaire stage.
  • Outsourcing and outstaffing companies with access to a client's code base, infrastructure or data.
  • Fintech, healthtech and HR-tech start-ups, where data sensitivity is particularly high.
  • Cloud and managed service providers (hosting, DevOps, support).

For Ukrainian companies, SOC 2 is often a way to address customer concerns about jurisdiction, business continuity and physical security. The report demonstrates that those risks are managed systematically.

What SOC 2 gives the business

  • Shorter sales cycles. Instead of answering hundreds of questionnaire items for every prospect, you send the report.
  • Access to the enterprise segment. Large customers, banks and insurers frequently will not start negotiations without SOC 2.
  • Real process maturity. Preparation forces you to tidy up access management, change management, backups and incident response.
  • Synergy with other frameworks. Many controls overlap with ISO 27001 and GDPR requirements; see SOC 2 vs ISO 27001 for how to choose.

The path to a SOC 2 report

The journey has two parts: readiness and the audit itself.

  1. Scoping. Which systems, products, teams and TSC criteria fall within the audit boundary.
  2. Gap analysis. Comparing the current state against the criteria and listing the gaps.
  3. Implementing controls. Policies, procedures, technical configuration (MFA, logging, encryption, backups), staff training.
  4. Evidence collection. Documentary proof that controls operate: logs, screenshots, tickets, reports.
  5. The CPA audit. The independent auditor tests the controls and issues the report.

The first four steps are handled by a readiness consultant. BALTUM runs the gap analysis, drafts the policies, helps configure controls and collect evidence, and supports you during the audit. The report itself is issued by the BALTUM group's US CPA firm in the United States; auditor independence is a mandatory requirement of the standard.

How long it takes and what it costs

Readiness for Type 1 at a small company usually takes 2–4 months; Type 2 takes 6–12 months including the observation period. The CPA audit fee for a small or mid-sized business is roughly $8–20k for Type 1 and $15–40k for Type 2; readiness cost depends on scope and the maturity of existing processes. See the detailed breakdown in How Much Does SOC 2 Cost.

Common mistakes

  • Buying a "policy template pack" and hoping that is enough. The auditor tests whether controls operate, not whether documents exist.
  • Putting the whole company in scope when the customer only cares about one product.
  • Starting a Type 2 observation period without a gap analysis, then discovering gaps halfway through.
  • Treating SOC 2 as a one-off project. A Type 2 report needs to be renewed annually.

Planning SOC 2 for your company? Send us a request and we will assess your scope, advise which report type to start with and give you realistic timelines and a readiness budget. Request a consultation and quote.