SOC 2 Compliance Requirements and Checklist Customers, partners, and auditors want proof before they'll sign a contract. Not promises. Proof. A security questionnaire lands in your inbox, and suddenly "we take security seriously" doesn't cut it anymore.

SOC 2 has become that proof. It's a framework developed by the AICPA for service organizations that store or process customer data, and for many Chicagoland small and mid-size businesses, it's now a condition of doing business with bigger clients or vendors. This article breaks down the requirements, the Trust Services Criteria, audit types, and a practical checklist you can actually use.

Key Takeaways

  • SOC 2 is voluntary but often customer-required: an auditor's opinion, not a pass/fail certificate
  • Security is the only mandatory criterion; the other four are optional based on your services
  • Type I checks control design at one point in time; Type II tests operating effectiveness over 3–12 months
  • Readiness means documented policies, technical controls, a readiness assessment, and ongoing monitoring

What Is SOC 2 and Why Does It Matter?

SOC 2 (System and Organization Controls 2) is an attestation report issued by a licensed CPA firm. It's not a government certification and no agency hands out a "SOC 2 certified" badge. What you get instead is a formal opinion, backed by audit evidence, on whether your controls meet specific criteria.

Who Needs to Be SOC 2 Compliant?

SaaS companies, cloud providers, and any vendor storing or processing customer data are the usual candidates. Most don't pursue SOC 2 out of curiosity — they get a security questionnaire from a prospective enterprise client and realize a SOC 2 report answers 80% of the questions in one document.

Is SOC 2 Certification Mandatory?

No. Unlike HIPAA or GDPR, there's no law requiring it. But it has become a de facto requirement for closing enterprise deals.

Large organizations routinely require vendors to produce a current SOC 2 report and resubmit annually, according to Dark Reading's reporting on SOC 2 attestation practices. Skip it, and you may find yourself disqualified from RFPs before you even get a call back.

The Five Trust Services Criteria Explained

The AICPA defines five Trust Services Criteria (2017 TSC with 2022 revised points of focus). You don't need all five — pick the ones that match your services and what customers expect to see in your report.

  • Security (mandatory): Access controls, firewalls, and risk management that protect systems from unauthorized access. Required baseline in every SOC 2 report.
  • Availability: Uptime commitments, disaster recovery, and whether systems meet stated SLAs.
  • Processing Integrity: Complete, accurate, authorized data processing — critical for billing and transaction platforms.
  • Confidentiality: Encryption and data classification for sensitive business information beyond personal data.
  • Privacy: Handling of PII and PHI, including consent and breach notification. Privacy overlaps heavily with HIPAA for healthcare-adjacent organizations.

Five SOC 2 Trust Services Criteria security availability confidentiality privacy

Most companies start with Security alone, then add Availability or Confidentiality when customers raise them in vendor questionnaires.

SOC 2 Compliance Requirements Checklist

There's no single universal checklist — your scope depends on your services, hosting model, and size. But these control areas show up in nearly every audit. Foundational requirements:

  • An information security program with documented policies, reviewed annually
  • Formal risk assessment, updated at least once a year
  • Vendor and third-party risk management processes Access management:
  • Role-based access controls tied to job function
  • Multifactor authentication (MFA) on all critical systems
  • Periodic access reviews to catch stale or excessive permissions
  • Logging and monitoring of access activity Technical controls:
  • Vulnerability scanning and penetration testing
  • Encryption at rest and in transit
  • Documented change management for system and software updates Incident response: A tested incident response plan with clear escalation paths and notification procedures. Ongoing evidence: An internal compliance evaluation program that collects evidence continuously, not just before the audit. This is where most small businesses stall — not because the requirements are complex, but because implementing 24/7 monitoring, MFA, SIEM, and MDR from scratch takes real technical bandwidth. LME Services helps small and mid-sized businesses build these controls as part of compliance readiness:
  • 24/7 SOC monitoring for suspicious activity
  • MFA included in cyber protection plans
  • SIEM tools that collect and analyze security events
  • MDR that pairs detection technology with a human response team

SOC 2 compliance checklist categories covering access management technical controls

SOC 2 Type I vs. Type II and the Audit Process

Type I and Type II reports answer different buyer questions. Type I shows your controls were designed correctly on a given date. Type II shows those controls worked over time.

Aspect Type I Type II
What it evaluates Control design at one point in time Control effectiveness over a period
Typical duration Weeks 3–12 months (commonly 6–12)
Customer expectation Often a starting point Now the standard most enterprise buyers expect

What Kinds of Tests Are Included in a SOC 2 Audit?

Auditors send evidence requests, walk through your controls, and test both design and actual operation. The result is one of four opinions:

  1. Unqualified (clean): No material issues found
  2. Qualified: Specific, limited exceptions noted
  3. Adverse: Material, pervasive problems
  4. Disclaimer: Insufficient evidence to form an opinion

Most companies aim for an unqualified opinion. A qualified opinion is not a dead end, but clients will expect a clear explanation of every exception.

How Do I Become SOC 2 Compliant?

Here is the typical path:

  1. Scope which Trust Services Criteria apply to your business
  2. Conduct a readiness assessment to find gaps
  3. Remediate those gaps (policies, access controls, technical fixes)
  4. Gather evidence continuously, not the week before the audit
  5. Engage a licensed CPA firm for the formal attestation

5-step SOC 2 compliance path from scoping to CPA attestation

LME Services handles preparation: designing controls, writing policies, closing gaps, and building evidence ahead of the audit. Clients are then paired with an AICPA-certified CPA firm for the independent attestation. The CPA does not build your controls; they evaluate them.

How Often Is SOC 2 Compliance Required?

Type II reports typically cover a rolling 12-month period. Most companies renew annually to keep the report current for customers and auditors, according to A-LIGN's SOC 2 guide. There's no law forcing this cadence — it's simply what the market expects.

Costs, Timeline, and How to Prepare

Costs vary widely depending on report type, scope, and organizational complexity. A-LIGN's published research puts SOC 2 audit costs generally between $20,000 and $150,000 or more, with first-time preparation and remediation adding to that range. Timeline expectations:

  • Type I audits: roughly 2-4 weeks for a point-in-time review of control design
  • Type II audits: a 3-12 month observation period, with 6-12 months typical, before the CPA signs off Type I is a one-time attestation of how controls are designed. Type II requires you to operate those controls through the full observation window so the auditor can test operating effectiveness. Before the formal audit, complete a readiness assessment so gaps surface on your timeline—not the auditor’s. Preparation typically includes:
  • Mapping current controls to the Trust Services Criteria
  • Closing security and process gaps
  • Documenting policies and gathering evidence
  • Building a compliance roadmap with owners and dates LME Services supports this groundwork for small and mid-sized businesses by identifying gaps, designing SOC controls, documenting policies, and staging the audit path—the same approach it uses for HIPAA and ISO readiness work.

SOC 2 Type I versus Type II audit timeline comparison chart

Frequently Asked Questions

How much does it cost to get SOC 2 Type 2 certified?

Cost depends on your company size, scope, and how much readiness or remediation work is needed before the audit. Get a custom quote from an auditor or compliance consultant rather than relying on a general estimate.

How do I become SOC 2 compliant?

Scope your Trust Services Criteria, remediate control gaps, gather evidence continuously, and engage a licensed CPA firm for the formal attestation. Preparation work and the audit itself are typically handled by different parties.

Who needs to be SOC 2 compliant?

SaaS companies, cloud providers, and any organization handling customer data on behalf of clients. It's usually driven by a customer or vendor security questionnaire, not a legal mandate.

Is SOC 2 certification mandatory?

No, it's voluntary. But it's become a de facto requirement for winning and keeping enterprise contracts, especially in SaaS and data-handling industries.

What are the SOC 2 compliance requirements?

Documented policies, access controls (including MFA), continuous monitoring, and risk management tied to whichever Trust Services Criteria apply to your business. Security is always mandatory.

What kinds of tests are included in a SOC 2 audit?

Auditors review evidence, walk through your controls, and test both design and operating effectiveness. The result is a formal opinion: unqualified, qualified, adverse, or disclaimer.