Live Founding Cohort open, limited seats remaining Back to main site →

What SOC 2 is and why US enterprises demand it

SOC 2 is a US commercial gate, not a regulatory obligation. If you sell SaaS to enterprise US customers, a Type II report is a contract requirement. This lesson walks what SOC 2 actually is, where the standard comes from, and why your enterprise buyer will not sign the MSA until you produce one.

Free preview 9 min read Verified
Legal basis
SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only). Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.

Here is the moment every Indian SaaS founder discovers SOC 2. You are three months into pursuing your first big US enterprise deal. The buyer has said yes. Legal is drafting the master service agreement. Then their security team emails a two-line request: "Please share your latest SOC 2 Type II report." You look at your co-founder. Neither of you has ever produced one. You Google. Two hours later you are staring at Vanta's pricing page and wondering whether 10,000 US dollars a year is a lot or a little for something you did not know existed this morning.

This lesson is written for that moment. What SOC 2 actually is, where it comes from, and why your enterprise buyer will not sign until you can produce one.

What SOC 2 is, one paragraph

SOC 2 is an attestation report issued by a licensed US Certified Public Accountant firm about the information security posture of a service organisation, based on a defined set of criteria called the Trust Services Criteria [L1-C1]. It is not a certification. It is not a stamp. It is a report, typically 40 to 80 pages long, written in a specific format, that says: this service organisation described its system this way, said its controls work this way, and here is what we tested and what we found. Your enterprise US customer reads the report and decides whether the description and the controls satisfy their vendor risk requirements. If yes, the deal proceeds. If no, or if the report does not exist, the deal does not proceed.

Where SOC 2 comes from

SOC 2 is issued under the American Institute of Certified Public Accountants (AICPA) attestation standards, specifically the Statement on Standards for Attestation Engagements No. 18 (SSAE 18) [L1-C2]. SSAE 18 sits on top of the older SSAE 16 which sat on top of an even older SAS 70. The regulatory family tree goes back to 1992. What is current now is SSAE 18, issued April 2016, currently effective as of the April 2026 codification. Every SOC 2 examination in the world today is done under SSAE 18.

The Trust Services Criteria that define what the auditor tests are a separate document, also published by AICPA. Current operative version: 2017 Trust Services Criteria with Revised Points of Focus (2022) [L1-C3]. That name matters. The criteria themselves were issued in 2017. In December 2022 AICPA published additional Points of Focus (the "what does this look like operationally" notes for each criterion) without changing the criteria themselves. So when a Big 4 partner says "the 2022 update", they mean the Points of Focus, not the criteria.

Verify. As of 22 August 2026 the AICPA Auditing Standards Board issued an Exposure Draft on 26 February 2026 proposing revisions to sections AT-C 105, 205 and 210 of SSAE 18. Comment period closed 30 June 2026. No final revised standard has been issued as of course pin date. This course teaches SSAE 18 as currently effective and flags the proposed revision for post-launch monitoring.

Why your US enterprise customer demands it

Three reasons, in the order they matter to your customer.

One: their vendor risk management programme requires it. Any enterprise buying SaaS in the US has an internal vendor risk framework that classifies vendors by data sensitivity and mandates specific assurance evidence for each tier. For anything that touches customer data (which is every SaaS you sell to them), a SOC 2 Type II report is the standard evidence artefact. Their VRM team cannot approve the vendor onboarding without it.

Two: their auditors will ask them where it is. If your customer is a public US company, their own external auditors will ask for a SOC 2 report from every material third-party service provider. This is because the customer is relying on your controls as part of their own control environment. Under COSO 2013 and PCAOB standards, they need to demonstrate they evaluated your controls. A SOC 2 Type II report is the standard evaluation artefact.

Three: their insurers require it. Cyber insurance policies for large US enterprises now typically require the insured to obtain SOC 2 or ISO 27001 reports from all material SaaS vendors. Without the report, the insurer can decline a data breach claim on the ground that the insured failed to verify vendor controls.

All three reasons stack. Your customer wants the deal too, but their VRM team, their auditors and their insurers are structurally prevented from signing off without the SOC 2 report in hand.

What SOC 2 is not

A short list of common founder misconceptions.

  • Not a certification. There is no "SOC 2 certified" logo. There is only a SOC 2 report. If a vendor is showing you a "SOC 2 Certified" badge on their homepage, they are technically misusing the term. The right phrasing is "SOC 2 Type II report available on request."
  • Not a legal or regulatory requirement. No US federal or state statute mandates SOC 2. Your customer's insurers, auditors and VRM team drive the demand.
  • Not a pass or fail test. The auditor issues an opinion, which can be unqualified (clean), qualified (one or more issues but not pervasive), adverse (pervasive control failures) or a disclaimer (auditor could not form an opinion). Most first-time filers who did the readiness work land on unqualified. Almost nobody publishes a qualified or adverse report; they fix the issues and re-audit.
  • Not one-and-done. A SOC 2 Type II report covers a specific period (typically 12 months). It expires. Your customer will ask for a new one every year, or a bridge letter covering the gap between reports.
  • Not the same as ISO 27001. Different framework, different standards body (ISO not AICPA), different report format, different reader. Both exist. Some customers want SOC 2. Some want ISO 27001. Some want both. Lesson 1.2 next walks the distinction.

The Indian SaaS picture

The Indian SaaS market has moved from 500 companies in 2018 to roughly 4,000 to 5,000 today competing for US enterprise wallet. Freshworks maintains a Trust Portal at freshworks.com/security showing SOC 2 Type II, ISO 27001, GDPR and HIPAA postures [L1-C4]. Zoho publishes a security page at zoho.com/security.html covering SOC 2, ISO 27001, GDPR, DPDP, HIPAA and PCI DSS [L1-C5]. Most unicorn-tier Indian SaaS now have SOC 2. Most Series A and early Series B companies are actively pursuing it or have just started. That is the reader of this course.

Next lesson: SOC 1 versus SOC 2 versus SOC 3 versus ISO 27001 versus FedRAMP. When each applies. Which report your customer actually wants to see when they ask for "your SOC report".

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
AICPA Trust Services Criteria 2017 (2022 PoF), 2017 TSC with Revised Points of Focus (2022) (Current operative TSC document) L1-C3
2017 Trust Services Criteria with Revised Points of Focus (2022). Five categories: Security (Common Criteria mandatory), Availability, Processing Integrity, Confidentiality, Privacy. Common Criteria structure CC1 through CC9. 2022 refresh added Points of Focus without altering criteria. Key 2022 additions: system documentation must include network and data-flow diagrams plus hardware inventory; asset retrieval and immediate access restriction on employee or contractor termination including remote workforce; patch management process with identification, testing, approval, verification.
AICPA SSAE 18, SSAE 18 Attestation Standards (April 2016) (Statement on Standards for Attestation Engagements No. 18) L1-C2
Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued by the AICPA Auditing Standards Board in April 2016. Currently effective as of the April 2026 codification. Applies to all attestation engagements including SOC 1 (SOC for Service Organizations relevant to financial reporting), SOC 2 (SOC for Service Organizations Trust Services Criteria), and SOC 3 (public-distribution short-form SOC 2). Structure: three engagement types defined at AT-C 105 (Examination, Review, Agreed-Upon Procedures). SOC 2 is an Examination engagement.
Public SOC 2 Posture, Freshworks Trust Portal (Freshworks security and SOC 2 posture (public)) L1-C4
Freshworks Trust Portal covers SOC 2 Type II report availability, ISO 27001, GDPR, HIPAA postures. Referenced as case material for Module 8 Lesson 1 Trust Portal publishing pattern.
Public SOC 2 Posture, Zoho Trust Page (Zoho security and compliance page (public)) L1-C5
Zoho public security page covers SOC 2, ISO 27001, GDPR, DPDP Act, HIPAA and PCI DSS postures. Referenced as case material for Module 8 Lesson 1.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The story of SOC 2
Module 2: Common Criteria Part 1: CC1 to CC5, governance and risk
  • CC1 Control Environment: tone at the top, board oversight, org structure
  • CC2 Communication and Information: internal comms, external commitments, the Trust Portal
  • CC3 Risk Assessment: asset inventory, threat identification, likelihood, impact, residual risk
  • CC4 Monitoring Activities: continuous monitoring, deficiency reporting, remediation tracking
  • CC5 Control Activities: selection, technology-general controls, segregation of duties
Module 3: Common Criteria Part 2: CC6 to CC9, operations
  • CC6 Logical and Physical Access Controls: IAM, MFA, provisioning, remote access, keys
  • CC7 System Operations: detection tooling, incident response, backup and recovery
  • CC8 Change Management: dev lifecycle, code review, testing, approval, deployment, rollback
  • CC9 Risk Mitigation: vendor risk, third-party risk, business continuity, insurance
  • The 2022 Revised Points of Focus: what auditors now specifically look for
Module 4: The optional four Trust Services Criteria
  • Availability TSC — the uptime criterion
  • Processing Integrity TSC — the transaction criterion
  • Confidentiality TSC — the trade-secret criterion
  • Privacy TSC — and the GDPR / DPDP Act 2023 / CCPA overlap
  • TSC decision matrix — which to add and when, by industry
Module 5: The Control Framework and Policy Pack
  • The Control Matrix — mapping TSC clauses to controls, owners and evidence
  • The 10-Policy Pack — draft skeletons your auditor will ask to see
  • Risk Assessment Framework — asset, threat, likelihood, impact, residual risk
  • Vendor Risk Register — the working register your auditor tests against CC9.2
  • Incident Response Plan and Tabletop Runbook
Module 6: Evidence Collection Operating Model
  • Continuous vs point-in-time evidence, and how the auditor samples
  • Buy vs Build: Vanta, Drata, Sprinto, Secureframe, Comply.ai, or in-house
  • Evidence types: what makes evidence auditor-quality vs unusable
  • The Evidence Collection Calendar, a twelve-month template
  • Audit trail hygiene: organising the evidence pack for the first 48 hours of fieldwork
Module 7: Selecting the Auditor and the Audit Cycle
  • What makes a SOC 2 auditor: licensing, independence, sector experience
  • The Auditor RFP and Selection Matrix: running Big 4 against mid-tier against boutique
  • The SOC 2 Engagement Letter, full SSAE 18 template
  • The audit cycle week by week, kickoff to report issuance
  • Auditor opinion types: unqualified, qualified, adverse, disclaimer
Module 8: Post-Audit and Continuous Compliance
  • Publishing the SOC 2 report on your customer trust portal
  • Answering vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report
  • The annual re-audit cycle and the bridge letter
  • Adding TSCs beyond Security: Availability, then Confidentiality, then Privacy
  • SOC 2 to ISO 27001 upgrade path and emerging AI controls