SOC 2
SOC 2 is an opinion someone signs, not a certificate you hang up.
SOC 2 is an attestation engagement. A licensed CPA firm examines the system you describe, tests the controls you designed against the Trust Services Criteria, and issues a report with an opinion in it that you share with customers under a confidentiality agreement. Security is mandatory. The other four criteria categories are a scoping decision with real cost attached. Sentinel is where the criteria mapping, the controls, the owners and the evidence live while the observation window runs.
Self-service signup opens shortly — we will set you up in the meantime
SOC 2 (Trust Services)
In scope- SOC 2 (Trust Services Criteria)71% ready45 criteria in the catalogue
Criteria mapped onto your own controls, each with an owner, a status and attached evidence. Figures are from the example workspace used throughout this site; Northstar Manufacturing Ltd. is fictional, and 71% ready is a readiness position rather than an audit opinion.
The deliverable
What is actually in the document, and who writes each part.
Worth knowing before you buy one, because four of the five sections are written by you rather than by the auditor — and the section that separates Type I from Type II is a section that either exists or does not.
- I
- Independent service auditor’s reportCPA firm
- The opinion, on the CPA firm’s letterhead, two or three pages long. It names the criteria in scope, the type of examination, and — for a Type II — the exact period covered. This is the part your customer’s security reviewer reads first and sometimes only.
- II
- Management’s assertionYou
- Your own written statement that the system description is accurate and the controls were suitably designed, and for a Type II that they operated effectively. You sign this. It is the reason a SOC 2 is an attestation rather than an inspection.
- III
- The system descriptionYou
- Written by you, against the AICPA description criteria. Infrastructure, software, people, procedures and data; the boundary; the criteria in scope; subservice organisations and how they are treated; and the complementary user entity controls your customers have to operate at their end. Usually the longest section and the one that takes the most drafting.
- IV
- Tests of controls and results — Type II onlyCPA firm
- The auditor’s procedures, control by control, with the result of each test and any deviations written out. A Type I has no Section IV at all, which is the whole difference in one line.
- V
- Other information provided by managementYou, unaudited
- Optional, and not covered by the opinion. This is where a management response to a deviation or a roadmap commitment goes. Reviewers know it is unaudited.
Structure
Five criteria categories, and only one is compulsory.
The Trust Services Criteria describe outcomes. They do not hand you a control list, which is the single biggest difference from ISO 27001 Annex A or the CIS Safeguards — and the reason two companies with the same report can look nothing alike.
- CCRequired
Security
The common criteria, and the only category you cannot leave out. Nine groupings: control environment, communication and information, risk assessment, monitoring activities and control activities — the five that align to the COSO components — then logical and physical access, system operations, change management, and risk mitigation.
- A1Common addition
Availability
Whether the system is available for operation and use as committed. Capacity management, environmental threats, and backup and recovery that has actually been tested. Add it when you have uptime commitments in a contract, which most software companies do.
- C1Common addition
Confidentiality
Whether information designated as confidential is identified, protected while retained, and disposed of when it should be. Cheaper to add than most teams expect, because much of the underlying work is already in the common criteria access controls.
- PI1Situational
Processing Integrity
Whether processing is complete, valid, accurate, timely and authorised. Genuinely relevant if you process transactions, payroll, claims or calculations on a customer’s behalf. Mostly noise if you do not — and it puts your product logic in audit scope.
- P1–P8Heaviest
Privacy
Notice, choice and consent, collection, use and retention and disposal, access, disclosure and notification, quality, and monitoring and enforcement — applied to personal information. The largest addition by a wide margin, and it commits you to operating a privacy programme, not just protecting a database. Include it when a customer or a regulator has actually asked, and not to look thorough.
Each criterion is accompanied by points of focus — considerations that help you decide whether a control addresses it. Points of focus are guidance, not requirements, and treating them as a checklist is how a scope quietly doubles.
A SOC 2 report is a description of your controls that somebody independent was willing to sign their name under. The description is yours. The signature is not.
Which is why the description is where readiness work actually lands. You write the boundary, you design the controls, you argue they address the criteria — and an independent firm decides whether it will put its name to that.
The choice
Type I and Type II differ by one section.
Everything else people say about the two follows from that. Section IV is the auditor’s testing, control by control, across a period — and a Type I does not have one.
| Type I | Type II | |
|---|---|---|
| What the opinion covers | Whether the description is fairly presented and the controls are suitably designed, as at one specified date. | All of that, plus whether the controls operated effectively throughout a stated period. |
| Section IV — tests of controls | Absent. That absence is the whole difference. | Present: the auditor’s procedures, control by control, with any deviations written out. |
| Observation window | None. | Three months is a common first window; annual cycles usually cover twelve. |
| Time to produce | Weeks, once the control design is finished. | The window, then fieldwork, then several weeks to a signed report. |
| What a reviewer concludes | The controls exist and are built sensibly. Nothing about whether anyone ran them. | The controls were operated. This is the report almost every vendor security review is asking for. |
| Where it earns its keep | One named buyer who has said it will unblock the contract while the Type II window runs. | Everywhere else, and every year after that. |
| The trap | Increasingly treated as insufficient on its own by enterprise security teams. | A control that started working in week ten produces deviations for weeks one to nine. |
- What the opinion covers
- All of that, plus whether the controls operated effectively throughout a stated period.
- Section IV — tests of controls
- Present: the auditor’s procedures, control by control, with any deviations written out.
- Observation window
- Three months is a common first window; annual cycles usually cover twelve.
- Time to produce
- The window, then fieldwork, then several weeks to a signed report.
- What a reviewer concludes
- The controls were operated. This is the report almost every vendor security review is asking for.
- Where it earns its keep
- Everywhere else, and every year after that.
- The trap
- A control that started working in week ten produces deviations for weeks one to nine.
- What the opinion covers
- Whether the description is fairly presented and the controls are suitably designed, as at one specified date.
- Section IV — tests of controls
- Absent. That absence is the whole difference.
- Observation window
- None.
- Time to produce
- Weeks, once the control design is finished.
- What a reviewer concludes
- The controls exist and are built sensibly. Nothing about whether anyone ran them.
- Where it earns its keep
- One named buyer who has said it will unblock the contract while the Type II window runs.
- The trap
- Increasingly treated as insufficient on its own by enterprise security teams.
Reports cover a closed period, so there is always a gap between the period end date and the day a customer asks. That gap is normally covered by a bridge letter from management confirming no material change since the report — a letter, not an audited document.
Readiness path
Six steps, and step four sets the date everything else hangs off.
Readiness is the work before the examination: the description written, the criteria mapped to controls that exist, the owners named, and the evidence habit established. The examination is what happens to a programme that is already running.
- 01
Decide the criteria and the boundary
Which categories beyond Security, and which system. Ask the customer who triggered this what their vendor policy names — adding Privacy because it sounded thorough is the most expensive unforced error on this page.
- 02
Write the system description
Draft Section III early, not the week before fieldwork. Writing the boundary honestly is what surfaces the subservice organisations, the shared administrative accounts and the legacy environment nobody wanted to mention.
- 03
Map the criteria to your own controls
SOC 2 gives you criteria, not controls. You write the control, name the owner, and argue it addresses the criterion. That freedom is why readiness work here is design work rather than a shopping list.
- 04
Close the design gaps, then set the window start
A control that does not exist yet cannot be tested. Fix first, then pick the date the observation window opens — because from that date forward, every gap is a deviation with evidence attached.
- 05
Operate through the observation window
Access reviews performed on schedule, changes ticketed and approved, incidents logged and closed, training completed, vendors reviewed. Collect as you go. Reconstructing three months of evidence at the end is how deviations get written up.
- 06
Fieldwork, then the report
The CPA firm requests populations, samples them, tests, and raises queries. Expect weeks between the window closing and the signed report, then annual periods after that with a bridge letter to cover the gap when a customer asks mid-cycle.
In Sentinel
Where the observation window is survived.
The hard part of a Type II is not the audit. It is month two of the window, when the access review was due last Friday and nobody has noticed.
Criteria mapping
Criteria you did not write, mapped to controls you did.
The common criteria and any additional categories you selected become requirements pointing at your own controls, each with a named owner. SOC 2 gives you outcomes; the control that satisfies one is a design decision, and it belongs in a register rather than in a document.
- 45 criteria — mapped onto a register of 26 controls shared with ISO 27001, NIST CSF 2.0 and CIS v8.1
- Named owners — 24 of 26 assigned, and the unowned ones visible instead of averaged away
- Test schedule and findings — the date a control was last checked, which is what a population request is asking about
| Control | Owner | Status | Evidence | Last tested |
|---|---|---|---|---|
| A.5.1Policies for information security | Priya Raman | Passed | Accepted | 28 Jul 2026 |
| A.5.18Access rights | Priya Raman | Passed | Accepted | 26 Jun 2026 |
| A.8.5Secure authentication | Priya Raman | Passed | Accepted | 14 Aug 2026 |
| A.8.13Information backup | Jordan Blake | Passed | Accepted | 18 Jun 2026 |
| A.8.2Privileged access rights | Priya Raman | Failed | Needs Review | 20 Aug 2026 |
| A.8.7Protection against malware | Jordan Blake | Tested | Accepted | 28 Aug 2026 |
| CC9.2Vendor and business partner risk management | Elena Kowalski | Failed | Accepted | 12 Aug 2026 |
| PR.AA-01Identities and credentials are managed | Unassigned | Not Tested | Missing | — |
- A.5.1Policies for information security
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 28 Jul 2026
- A.5.18Access rights
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 26 Jun 2026
- A.8.5Secure authentication
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 14 Aug 2026
- + 5 more in the workspace
Evidence
Sampling is why retrofitting fails.
The auditor picks dates across the whole window, so a quarter you skipped is visible from the outside. Evidence carries a status and an expiry date here, so a missed review shows up as expired in week six rather than as a deviation in Section IV.
- Status and expiry — on every item: Accepted, Under Review, Pending, Expired, Missing
- 1 expired, 1 missing — surfaced continuously in the example workspace, not reconstructed at the end
- Contemporaneous by default — attached the day the control operated, which is the only kind of evidence sampling accepts
Evidence status
26 controls- Accepted41
- Needs Review2
- Pending1
- Expired1
- Missing1
Register
Expiring first| Evidence | Control | Owner | Status | Validity |
|---|---|---|---|---|
| Backup restore test report — Q3 2026 | A.8.13 | Jordan Blake | Missing | Due 30 Sep 2026 |
| Penetration test report — external (2025) | A.8.8 | Priya Raman | Expired | Expired 20 Jul 2026 |
| Privileged account inventory | A.8.2 | Priya Raman | Needs Review | Uploaded 4 Sep 2026 |
| Statement of Applicability — draft v3 | C.6 | Elena Kowalski | Pending | Due 31 Aug 2026 |
| MFA enforcement — Microsoft 365 Conditional Access | A.8.5 | Priya Raman | Accepted | Valid to 14 Aug 2027 |
| EDR coverage report — 98% of endpoints | A.8.7 | Jordan Blake | Accepted | Valid to 28 Nov 2026 |
- Backup restore test report — Q3 2026
- Control
- A.8.13
- Owner
- Jordan Blake
- Status
- Missing
- Validity
- Due 30 Sep 2026
- Penetration test report — external (2025)
- Control
- A.8.8
- Owner
- Priya Raman
- Status
- Expired
- Validity
- Expired 20 Jul 2026
- Privileged account inventory
- Control
- A.8.2
- Owner
- Priya Raman
- Status
- Needs Review
- Validity
- Uploaded 4 Sep 2026
- + 3 more in the workspace
Design gaps
A gap with a date is what lets you choose a window start.
Design gaps become assigned work in the product’s own horizons. That is what makes the window-start conversation a plan rather than a hope — you can see what is finished, what is in flight and what will not be ready.
- Critical Now → Strategic Projects — the product’s real horizons, not a flat backlog
- Owner and due date on every row — so the design gap and its closure sit in the same place
- Audit engagement workspace — somewhere to keep requests, populations and the artefacts you handed over, so next year starts from a record
| Action | Module | Owner | Priority | Due | Status |
|---|---|---|---|---|---|
| Run and document the Q3 backup restore test | Audit | Jordan Blake | Critical | 30 Sep 2026 | Not started |
| Deploy privileged access management for shared admin accounts | Risk | Priya Raman | Critical | 15 Oct 2026 | In progress |
| Obtain SOC 2 report from Great Lakes Logistics | Vendors | Elena Kowalski | High | 05 Oct 2026 | In progress |
| Approve the Data Retention & Disposal Policy | Policies | Dana Whitfield | High | 10 Oct 2026 | Not started |
| Tabletop exercise with plant leadership — ransomware scenario | Risk | Dana Whitfield | Medium | 20 Nov 2026 | Not started |
- Run and document the Q3 backup restore test
- Module
- Audit
- Owner
- Jordan Blake
- Priority
- Critical
- Due
- 30 Sep 2026
- Status
- Not started
- Deploy privileged access management for shared admin accounts
- Module
- Risk
- Owner
- Priya Raman
- Priority
- Critical
- Due
- 15 Oct 2026
- Status
- In progress
- Obtain SOC 2 report from Great Lakes Logistics
- Module
- Vendors
- Owner
- Elena Kowalski
- Priority
- High
- Due
- 05 Oct 2026
- Status
- In progress
- + 2 more in the workspace
Evidence
What fieldwork asks you for.
Not exhaustive, and your control design decides the rest. But these come up in nearly every examination — and the rows marked Recurring are where sampling bites, because the auditor picks dates across the whole window rather than the ones you would choose.
| Evidence | Cadence | What fieldwork does with it |
|---|---|---|
| System description and boundary | Foundational | Approved by management, and matching what the environment actually looks like. |
| Policies, approved and communicated | Foundational | With evidence of acknowledgement, not just a file with a version number. |
| Risk assessment, including fraud risk | Foundational | The common criteria ask for fraud explicitly. Most first drafts omit it. |
| Organisation chart and role definitions | Foundational | Who reports to whom, and who has authority over security decisions. |
| Onboarding and offboarding records | Recurring | Access granted on a request, and revoked with a date you can point at. |
| User access reviews, production and administrative | Recurring | Reviewer, population, date, and what changed as a result. |
| Change management records | Recurring | Changes tied to an approval and a review, sampled across the whole window. |
| Vulnerability scanning and remediation tracking | Recurring | Scan output plus the ticket that closed the finding. |
| Vendor and subservice organisation reviews | Recurring | Which providers are carved out, and what you assessed for the rest. |
| Backup restoration test results | Event-driven | Only if Availability is in scope — and then a real restore, with a date. |
| Incident records and post-incident review | Event-driven | An incident handled well reads better than an empty log. |
| Security awareness training completion | Time-bound | By person and date, covering everyone who was employed during the window. |
| Background check records | Time-bound | For hires inside the window, subject to what local law permits. |
| Management or board oversight minutes | Time-bound | Evidence that someone with authority reviewed security, on a cadence. |
Straight answers
Honest limitations.
Four things worth understanding before the budget is approved, and one about us.
- The scope is yours to draw
- You define the system boundary and select the criteria. A report can legitimately cover one product and exclude the rest of the business, so a careful reviewer reads Section III before the opinion.
- It is a period, not a state
- A Type II describes a window that has already closed. It says nothing about today, which is what bridge letters exist to paper over and what reviewers are right to probe.
- Your customers inherit work
- Complementary user entity controls are the things your customers must do for your controls to function. They are listed in the description, and they are frequently ignored by both sides.
- Readiness is not an outcome
- Being ready means the description is written, the controls exist with owners, and the evidence is current. The opinion remains the CPA firm’s judgement, and deviations happen.
Questions
Asked on nearly every first call.
Timelines, scope creep, exceptions, and what you are allowed to say on your website afterwards.
How long until we can hand a customer a Type II report?
Is a Type I worth paying for, or should we go straight to Type II?
Which criteria should we include beyond Security?
Our report has exceptions in Section IV. Did we fail?
Can we describe ourselves as SOC 2 certified?
Can CyberWave perform our SOC 2 examination?
Map the criteria before you book the window.
A first honest pass over the common criteria takes an afternoon and usually moves the window start date — which is cheaper to discover now than in Section IV.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required