Executive Summary
Every growing SaaS and services company eventually hits the same wall: a prospect's security team asks for a SOC 2 Type II report, and the deal stalls until one exists. This guide is written for the team facing that request for the first time and trying to get from zero to a clean report without derailing engineering.
SOC 2 is an AICPA attestation built on the Trust Services Criteria. A Type II report differs from a Type I in one decisive way: it tests whether your controls operated effectively across an observation period — commonly six to twelve months — rather than merely being well designed on a single day. That temporal requirement is what shapes the entire project plan.
The hardest part of SOC 2 Type II is not the technology. It is running your controls consistently, and capturing proof they ran, every day for months.
This guide walks the full lifecycle as a project:
- Plan — set scope, pick criteria, assign owners, and choose Type I first or straight to Type II.
- Prepare — write policies, stand up controls, and run a readiness assessment to find gaps.
- Operate — run the observation period so evidence accumulates continuously.
- Audit — work the auditor's evidence requests to a clean opinion.
- Sustain — renew annually with no coverage gaps.
We frame the work as sequential milestones so a lean team can budget time and effort realistically.
Deciding Your Path: Type I First or Straight to Type II
Before any control work begins, make one strategic choice that shapes your timeline and budget.
The two routes
- Type I then Type II: Obtain a point-in-time Type I report first (design only), then start the Type II observation window. This gives you an early artifact to show prospects and a rehearsal of the audit process.
- Straight to Type II: Skip the Type I and begin the observation period as soon as controls are in place, producing only the more valuable Type II report.
How to choose
Choose Type I first when you need something to hand a customer immediately, or when your team is new to audits and benefits from a low-stakes dry run. Choose straight to Type II when your controls are already mature and you want to avoid the cost of two engagements.
Set the observation window
Type II periods typically run three, six, or twelve months. A first report often uses a shorter window (three to six months) to reach a deliverable faster; renewals usually extend to a full twelve months for continuous coverage.
The window cannot start until controls are actually operating. Every gap you leave unremediated pushes the start date — and your report — later.
Step One — Scope and Criteria Selection
The planning phase fixes two variables that govern everything downstream: what systems are in scope and which Trust Services Criteria you commit to.
Draw the system boundary
Define the system as the specific product and the infrastructure, code, people, and data that deliver it. Keep unrelated corporate IT, internal tools, and other product lines outside the boundary unless customers expect them included.
Select only the criteria you need
- Security (Common Criteria) is always required.
- Availability matters if you make uptime commitments in SLAs.
- Confidentiality matters if you handle customer data under confidentiality obligations.
- Processing Integrity matters for transaction or data-processing platforms where accuracy is a promise.
- Privacy matters when you handle personal information under privacy commitments.
Anchor the choice in contracts
Read your customer agreements and DPA commitments. The criteria you select should mirror the promises you have actually made — no more, no less. Each added criterion brings new controls to operate and evidence for the full period.
A common first-timer mistake is selecting all five criteria to look thorough. This multiplies work for no commercial benefit. Most first reports are Security-only, sometimes plus Availability or Confidentiality.
Step Two — Policies, Controls, and Ownership
With scope set, build the control environment. SOC 2 expects both documented governance and working technical controls.
Write the foundational policies
Auditors expect a coherent set of policies: information security, access control, change management, incident response, risk assessment, vendor management, business continuity, and acceptable use. These are not shelfware — the auditor tests whether you follow them.
Stand up the technical controls
- Access: centralized identity, enforced MFA, role-based access, scheduled access reviews, and automated deprovisioning.
- Change management: peer-reviewed code, automated testing gates, and recorded deployment approvals.
- Operations: centralized logging, alerting, and a documented, tested incident response process.
- Vendor risk: a register of subservice organizations with their own SOC 2 or equivalent evidence.
Assign owners early
Map each control to a named owner across identity, engineering, and security operations. Controls without owners are the ones that quietly stop running mid-window and produce audit exceptions.
Policies describe what you promise to do; controls are you doing it. A Type II auditor checks that the two match across the entire observation period.
Step Three — The Readiness Assessment
A readiness assessment is a full rehearsal of the audit against your selected criteria, performed before the observation window opens. Skipping it is the surest way to enter the window with hidden gaps.
What it uncovers
- Policies that exist but are not actually followed.
- Controls that operate informally and leave no evidence.
- Missing governance artifacts — no risk assessment, no vendor reviews, no incident-response test.
- Cloud misconfigurations that violate your own stated controls.
The gap-remediation loop
For each gap, decide whether to implement a new control, formalize an existing informal process, or adjust scope. Remediate everything before the window opens, because a control that isn't operating on day one cannot be tested as effective across the period.
Where an external partner helps
A readiness assessment benefits from an outside perspective that knows how auditors think. GuardsArm's compliance readiness engagements run this gap analysis, prioritize remediation by risk and effort, and help teams stand up the monitoring and incident-response controls that first-timers most often lack.
Treat the readiness assessment as the real deadline. Once you pass it cleanly, the observation period becomes a matter of steady operation rather than frantic building.
Step Four — Running the Observation Period
The observation period is where a Type II is won or lost. For the full window, controls must operate and produce a continuous evidence trail.
Evidence accumulates, it isn't manufactured
Auditors sample across the period: access reviews from particular months, change tickets, triaged alerts, onboarding and offboarding records, and configuration exports. If those records exist naturally because your systems create them, the audit is straightforward. If you have to reconstruct them, you will have gaps.
Use continuous monitoring tooling
- Deploy a compliance automation platform (Vanta, Drata, Secureframe, or similar) to continuously pull cloud and SaaS configuration evidence and flag drift.
- Route approvals, reviews, and incidents through ticketing systems that timestamp and retain records.
Watch for mid-window drift
The classic failure is a control that runs in month one, lapses in month three, and resumes in month five. The auditor's sampling is designed to catch exactly that pattern.
Continuous monitoring is not only an audit convenience. Well-logged, continuously operating detection and response — the kind GuardsArm delivers as a managed service — is genuine security that happens to satisfy the CC7 operations criteria.
Step Five — The Audit and the Opinion
When the window closes, the CPA firm performs fieldwork: reviewing your system description, testing control design, and sampling evidence to test operating effectiveness.
Managing evidence requests
The auditor issues a request list. Respond with organized, clearly labeled evidence tied to specific controls and dates. Disorganized responses extend the engagement and frustrate everyone.
Understanding exceptions
If a sample shows a control did not operate as intended, the auditor records an exception. One or two exceptions with clear management responses rarely sink a report — customers read them in context. Pervasive exceptions lead to a qualified opinion.
The final report
The deliverable includes the auditor's opinion, management's assertion, the system description, and the detailed tests and results. Aim for an unqualified (clean) opinion. Share the report under NDA with prospects through your security review process.
Only a licensed CPA firm can issue the SOC 2 report. Keep your readiness partner and your audit firm separate so the auditor's independence — and therefore the report's credibility — is beyond question.
Step Six — Renewal and Continuous Compliance
A first report is the beginning of a recurring obligation. Enterprise buyers expect an unbroken chain of Type II reports year after year.
Plan for back-to-back windows
Schedule each new observation period to begin the day the previous one ends. Any gap between periods appears in the report timeline and prompts uncomfortable questions in customer security reviews.
Keep the program alive
- Re-run your risk assessment annually and whenever the architecture materially changes.
- Refresh vendor reviews as subservice organizations change.
- Extend controls to new systems and products before they enter customer-facing use.
- Hold periodic internal reviews so control drift is caught internally, not by the auditor.
Mature toward continuous assurance
The goal is a state where evidence is always current and a report can be produced on demand. Continuous-monitoring dashboards and clear control ownership make renewal routine rather than a repeat scramble.
The teams that find SOC 2 painful treat it as an annual event. The teams that find it easy treat it as an operating discipline — one GuardsArm helps embed so that each renewal is a formality, not a project.
Key Takeaways
- 1.Decide early between Type I first (a rehearsal and early artifact) or straight to Type II; the choice sets your timeline and budget.
- 2.Fix scope and select only the Trust Services Criteria your contracts require — most first reports are Security-only, sometimes plus Availability or Confidentiality.
- 3.Run a readiness assessment and remediate every gap before the observation window opens; a control not operating on day one can't be tested as effective across the period.
- 4.During the window, let evidence accumulate naturally through continuous-monitoring tooling and ticketed workflows rather than reconstructing records before fieldwork.
- 5.Renew annually with no coverage gaps and embed control ownership so SOC 2 becomes an operating discipline, not a yearly scramble.
Sources & Further Reading
- AICPA Trust Services Criteria (TSP Section 100), 2017 with 2022 revised points of focus
- AICPA SOC 2 Guide: Reporting on Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy
- COSO Internal Control — Integrated Framework
- AICPA Statement on Standards for Attestation Engagements (SSAE No. 18)
- NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations