SOC 2 & ISO 27001
What is SOC 2, and does my business need it?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
SOC 2 is an independent audit report, defined by the AICPA, that shows how a service organization protects customer data against criteria for security and, optionally, availability, confidentiality, processing integrity, and privacy. It is not a law, so no one is legally required to have it — but if you are a SaaS or B2B vendor that handles other companies' data, your enterprise customers will increasingly require a SOC 2 report before they buy. In practice that makes it commercially essential for many technology companies.
What SOC 2 actually is
SOC 2 (System and Organization Controls 2) is an attestation performed by an independent CPA firm against the AICPA's Trust Services Criteria. Security (the 'common criteria') is always included; you can add availability, confidentiality, processing integrity, and privacy depending on what matters to your customers.
The output is a report — not a pass/fail certificate — describing your controls and the auditor's findings. Customers read it to gain assurance that you handle their data responsibly.
Who needs SOC 2
SOC 2 is aimed at service organizations that store or process customer data — most commonly SaaS providers, cloud platforms, and B2B vendors. You likely need it if:
- Enterprise prospects ask for a SOC 2 report (or send security questionnaires) during procurement.
- You sell software or services that handle your customers' sensitive or regulated data.
- You want to shorten sales cycles by answering security due diligence with one trusted report.
Is it mandatory?
No law mandates SOC 2 — it is driven by the market, not regulators. But for many SaaS companies it is effectively a requirement to win mid-market and enterprise deals, because buyers use it to vet vendors. If your customers are not asking yet, a smaller business may start with a readiness assessment and pursue the full report when demand appears.
Frequently asked questions
It is not legally mandatory, but it is commercially expected. Enterprise buyers commonly require a SOC 2 report before purchasing, so for B2B SaaS it often becomes a practical prerequisite to closing larger deals.
SOC 2 is a North American attestation report against the AICPA's Trust Services Criteria; ISO 27001 is an international certification of an information security management system. They overlap heavily. See our answer on choosing between SOC 2 and ISO 27001.
A penetration test is not strictly mandated by the criteria, but auditors and customers widely expect one as evidence of a mature security program, and it is considered a best practice for SOC 2.
Keep exploring
All SOC 2 & ISO 27001What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I assesses control design at a point in time; Type II tests operating effectiveness over months. Compare the two, plus typical timeline and cost drivers.
ReadSOC 2 & ISO 27001SOC 2 vs ISO 27001 — which should we pursue first?
SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadSOC 2 & ISO 27001How much does SOC 2 cost and how long does it take?
How much does SOC 2 cost and how long does it take? Learn the real cost drivers — readiness vs audit fees, scope, Type I vs Type II — and a realistic timeline.
ReadSOC 2 & ISO 27001What documents and evidence do you need for a SOC 2 audit?
What documents and evidence do you need for a SOC 2 audit? A plain-language checklist of policies, system descriptions, and proof your controls operate.
ReadSOC 2 & ISO 27001What are the most common gaps found in a SOC 2 readiness assessment?
The most common gaps found in a SOC 2 readiness assessment — missing policies, access controls, evidence, vendor reviews, and monitoring — and how to close them.
Read