Here is the moment every Indian SaaS founder discovers SOC 2. You are three months into pursuing your first big US enterprise deal. The buyer has said yes. Legal is drafting the master service agreement. Then their security team emails a two-line request: "Please share your latest SOC 2 Type II report." You look at your co-founder. Neither of you has ever produced one. You Google. Two hours later you are staring at Vanta's pricing page and wondering whether 10,000 US dollars a year is a lot or a little for something you did not know existed this morning.
This lesson is written for that moment. What SOC 2 actually is, where it comes from, and why your enterprise buyer will not sign until you can produce one.
What SOC 2 is, one paragraph
SOC 2 is an attestation report issued by a licensed US Certified Public Accountant firm about the information security posture of a service organisation, based on a defined set of criteria called the Trust Services Criteria [L1-C1]. It is not a certification. It is not a stamp. It is a report, typically 40 to 80 pages long, written in a specific format, that says: this service organisation described its system this way, said its controls work this way, and here is what we tested and what we found. Your enterprise US customer reads the report and decides whether the description and the controls satisfy their vendor risk requirements. If yes, the deal proceeds. If no, or if the report does not exist, the deal does not proceed.
Where SOC 2 comes from
SOC 2 is issued under the American Institute of Certified Public Accountants (AICPA) attestation standards, specifically the Statement on Standards for Attestation Engagements No. 18 (SSAE 18) [L1-C2]. SSAE 18 sits on top of the older SSAE 16 which sat on top of an even older SAS 70. The regulatory family tree goes back to 1992. What is current now is SSAE 18, issued April 2016, currently effective as of the April 2026 codification. Every SOC 2 examination in the world today is done under SSAE 18.
The Trust Services Criteria that define what the auditor tests are a separate document, also published by AICPA. Current operative version: 2017 Trust Services Criteria with Revised Points of Focus (2022) [L1-C3]. That name matters. The criteria themselves were issued in 2017. In December 2022 AICPA published additional Points of Focus (the "what does this look like operationally" notes for each criterion) without changing the criteria themselves. So when a Big 4 partner says "the 2022 update", they mean the Points of Focus, not the criteria.
Verify. As of 22 August 2026 the AICPA Auditing Standards Board issued an Exposure Draft on 26 February 2026 proposing revisions to sections AT-C 105, 205 and 210 of SSAE 18. Comment period closed 30 June 2026. No final revised standard has been issued as of course pin date. This course teaches SSAE 18 as currently effective and flags the proposed revision for post-launch monitoring.
Why your US enterprise customer demands it
Three reasons, in the order they matter to your customer.
One: their vendor risk management programme requires it. Any enterprise buying SaaS in the US has an internal vendor risk framework that classifies vendors by data sensitivity and mandates specific assurance evidence for each tier. For anything that touches customer data (which is every SaaS you sell to them), a SOC 2 Type II report is the standard evidence artefact. Their VRM team cannot approve the vendor onboarding without it.
Two: their auditors will ask them where it is. If your customer is a public US company, their own external auditors will ask for a SOC 2 report from every material third-party service provider. This is because the customer is relying on your controls as part of their own control environment. Under COSO 2013 and PCAOB standards, they need to demonstrate they evaluated your controls. A SOC 2 Type II report is the standard evaluation artefact.
Three: their insurers require it. Cyber insurance policies for large US enterprises now typically require the insured to obtain SOC 2 or ISO 27001 reports from all material SaaS vendors. Without the report, the insurer can decline a data breach claim on the ground that the insured failed to verify vendor controls.
All three reasons stack. Your customer wants the deal too, but their VRM team, their auditors and their insurers are structurally prevented from signing off without the SOC 2 report in hand.
What SOC 2 is not
A short list of common founder misconceptions.
- Not a certification. There is no "SOC 2 certified" logo. There is only a SOC 2 report. If a vendor is showing you a "SOC 2 Certified" badge on their homepage, they are technically misusing the term. The right phrasing is "SOC 2 Type II report available on request."
- Not a legal or regulatory requirement. No US federal or state statute mandates SOC 2. Your customer's insurers, auditors and VRM team drive the demand.
- Not a pass or fail test. The auditor issues an opinion, which can be unqualified (clean), qualified (one or more issues but not pervasive), adverse (pervasive control failures) or a disclaimer (auditor could not form an opinion). Most first-time filers who did the readiness work land on unqualified. Almost nobody publishes a qualified or adverse report; they fix the issues and re-audit.
- Not one-and-done. A SOC 2 Type II report covers a specific period (typically 12 months). It expires. Your customer will ask for a new one every year, or a bridge letter covering the gap between reports.
- Not the same as ISO 27001. Different framework, different standards body (ISO not AICPA), different report format, different reader. Both exist. Some customers want SOC 2. Some want ISO 27001. Some want both. Lesson 1.2 next walks the distinction.
The Indian SaaS picture
The Indian SaaS market has moved from 500 companies in 2018 to roughly 4,000 to 5,000 today competing for US enterprise wallet. Freshworks maintains a Trust Portal at freshworks.com/security showing SOC 2 Type II, ISO 27001, GDPR and HIPAA postures [L1-C4]. Zoho publishes a security page at zoho.com/security.html covering SOC 2, ISO 27001, GDPR, DPDP, HIPAA and PCI DSS [L1-C5]. Most unicorn-tier Indian SaaS now have SOC 2. Most Series A and early Series B companies are actively pursuing it or have just started. That is the reader of this course.
Next lesson: SOC 1 versus SOC 2 versus SOC 3 versus ISO 27001 versus FedRAMP. When each applies. Which report your customer actually wants to see when they ask for "your SOC report".