Introduced by AICPA in 2010, SOC 2 is a framework that helps service providers protect data and client privacy. Based on five trust principles – security, availability, processing integrity, confidentiality, and privacy – it applies to SaaS companies, vendors, and third-party partners.
SOC 2 scope is set by which of the five Trust Services Criteria you include. Security is the only one required in every report. The other four are added based on what you commit to customers and what your buyers actually ask for.
| TSC | Requirement | Scope In When |
|---|---|---|
| Security (CC1–CC9) | Always | Every SOC 2 Report. Also called the Common Criteria |
| Availability | Optional | You carry uptime SLAs or service credits |
| Confidentiality | Optional | You handle customer trade secrets, contract or M&A data |
| Processing Integrity | Optional | You process transactions where accuracy is the product, like payments, payroll, billing |
| Privacy | Optional | You handle personal information across its lifecycle |
Scope discipline is the main lever on cost and timeline. Each additional criterion adds controls, evidence and audit hours. Most first-time SaaS organisations scope Security alone, or Security plus Confidentiality and Availability.
Criteria can be added in a later cycle without starting over. The Common Criteria evidence carries forward. Over-scoping the first report is the most common and most expensive mistake we see.
A Type 1 shows the controls you designed. A Type 2 shows that you operated them: auditors sampled access reviews that were genuinely performed each month along with the tickets closed, and alerts the alerts triaged.
| Particulars | SOC 2 Type 1 | SOC 2 Type 2 |
|---|---|---|
| Tests | Control design at a single date | Control design and operating effectiveness over a period |
| Period | Point in time | Observation window, minimum 3 months |
| Evidence | Current state | Sampled across the entire window |
| Cost | Lower | Higher |
| Buyer Acceptance | Sometimes accepted as an interim signal | What enterprise procurement actually asks for |
The observation window cannot be compressed. It is the one part of a SOC 2 timeline that money cannot shorten, which is why timeline, not fee, is usually the real pressure when a deal is waiting on a report.
A SOC 2 report contains the CPA firm's formal opinion. There are four:
Controls were designed and, for Type 2, operated effectively with no material exceptions. The outcome organizations want.
Controls were broadly effective, but specific exceptions were identified and are named in the report.
Controls were largely ineffective.
The auditor could not form a conclusion, usually from insufficient evidence or access.
A qualified opinion is not automatically deal-breaking. Exceptions appear in the report alongside a management response, and buyers generally accept a named exception with a credible, dated remediation plan. Kratikal's role is to make sure nothing in the report is a surprise to you.
Gap Assessment compares an organization’s current security posture with industry standards and SOC 2 requirements. It prepares organizations for the SOC 2 process by identifying gaps, providing essential insights, and recommending controls needed to address deficiencies.
SOC 2 outlines how to handle a customer's data using five principles: integrity, confidentiality, availability, and privacy. Information security, access control, risk assessment, mitigation, incident policy, and other policies must be documented to obtain SOC 2 attestation.
This evaluation ensures drafted policies are implemented and followed across the organization while strengthening reporting and attestation. Its findings help classify threats by risk level, enabling organizations to take appropriate and timely corrective action.
After completing the above stages, your organization is prepared for CPA audit fieldwork. The audit thoroughly evaluates SOC 2 compliance, identifies areas needing attention, and verifies control effectiveness over time. Type 2 audits typically take longer than Type 1 due to the operational evidence.
Finally, we help you complete the SOC 2 attestation by reviewing documentation requirements and validating control implementation. A licensed CPA firm then issues the SOC 2 attestation report, providing its formal opinion on your organization’s controls.
SOC 2 is not mandated by Indian law, but it is often required by customers, partners, and global buyers. Without it, organizations may face longer sales cycles, lost business opportunities, and reduced customer trust.
B2B SaaS
Healthcare
Fintech and Payments
IT Services, BPO and KPO
Data, Analytics and AI Vendors
Processing US Customer Data as a Sub-Processor
We sincerely appreciate the support provided by Kratikal in helping us successfully achieve compliance with the SOC 2 Type 2 Report. Your team's expertise, timely guidance, and thorough approach played a crucial role in this accomplishment. Thank you for being a dependable partner in our compliance journey.
We appreciate the effort and thoroughness applied in conducting the SOC 2 Type II audit and preparing the corresponding report. The report provides a comprehensive evaluation of our internal controls relevant to the Trust Services Criteria, particularly Security, Availability, Confidentiality, Processing Integrity and Privacy. Overall, the SOC 2 report effectively demonstrates the maturity and reliability of our control environment. We thank the audit team for their diligence and professionalism throughout the engagement.
Routine access reviews, change management, and incident response strengthen security with consistent monthly evidence.
Independent CPA assurance validates your controls and strengthens customer confidence in data security.
A SOC 2 report streamlines security reviews, reducing questionnaires, follow-ups, and evidence collection.
Shared controls simplify future compliance with ISO 27001, HIPAA, and GDPR frameworks.
Readiness takes 3 to 6 months. Type 1 follows shortly after. Type 2 adds an observation window of 3 to 12 months, so expect 6 to 12 months total.
No. SOC 2 is an attestation. A licensed CPA firm examines your controls and issues a report containing its opinion. There is no certificate and no certifying body.
No. Type 1 is optional and you can go directly to Type 2. Type 1 helps when you need a shareable report quickly. Enterprise buyers want Type 2 regardless.
No. That is an ISO 27001 document. SOC 2 uses a system description and an RFI tracker mapping evidence to the Trust Services Criteria you select.
Security, availability, processing integrity, confidentiality and privacy. Security is the only one required in every report. The other four are optional, scoped to your customer commitments.
There is no formal expiry, but the market treats reports as current for twelve months from the observation period's end. Older reports need a bridge letter or fresh audit.
A management statement covering the gap between your last report and the next observation window, confirming no material control changes. It is a stopgap, not a current report.
SOC 1 covers financial reporting controls. SOC 2 covers the Trust Services Criteria and is what enterprise buyers request. SOC 3 is a public summary, not a substitute.
Four: unqualified (no material exceptions), qualified (specific exceptions identified), adverse (controls largely ineffective), and disclaimer (auditor could not conclude). A qualified opinion needs a documented remediation plan.
SOC 2 is a US-oriented annual attestation report. ISO 27001 is a three-year international certificate. Controls overlap heavily. The answer usually depends on where your buyers are.
No law requires it. The demand comes from buyers: US and European enterprises routinely require a SOC 2 Type 2 report before onboarding Indian vendors.