What is SOC 2 Type II?
SOC 2 Type II is an audit framework developed by the AICPA (American Institute of CPAs) that evaluates a service organization's controls over a period of time typically 6 or 12 months. Unlike SOC 2 Type I which only checks that controls exist at a single point in time, Type II tests whether those controls operated effectively over the audit period. This is what enterprise customers, investors, and partners ask for when they want proof that you take security seriously.
Step 1 Define your scope
The first decision is which Trust Services Criteria (TSC) to include in your audit. Security (CC) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional add-ons. Most SaaS startups start with Security only, adding Availability if their customers have uptime SLAs. Get this wrong and you'll either over-scope (costing time and money) or under-scope (failing to satisfy enterprise requirements).
- →Security (CC) always required
- →Availability required for SaaS with uptime guarantees
- →Confidentiality required for data handling assurances
- →Processing Integrity required for financial, healthcare processing
- →Privacy required for consumer data handling
Step 2 Gap assessment
Before you can remediate, you need to know where you stand. A gap assessment maps your current practices against every control in the selected criteria. Expect to find gaps in change management, vendor reviews, and access recertification these are the most common failure points for first-time audits. Document everything: what control exists, how it works, who owns it, and what evidence will be collected.
Step 3 Build your policy library
SOC 2 requires documented policies covering information security, access control, incident response, change management, risk assessment, and vendor management at minimum. Auditors will review both the existence of these policies and evidence that employees have acknowledged them. Use templates as a starting point but ensure they reflect how your organization actually operates, not an idealized version.
Step 4 Implement and test controls
This is where most of the work happens. Every control needs to be implemented, tested, and generating evidence. The good news: most modern cloud environments already generate the logs and configuration data that constitute SOC 2 evidence. The work is connecting your tools, ensuring evidence is being captured correctly, and fixing gaps before your auditor sees them.
- →Access control: SSO, MFA, provisioning/deprovisioning workflows
- →Change management: code review, deployment approvals, change records
- →Vulnerability management: scanning, patching SLAs, penetration testing
- →Incident response: documented runbooks, tested response procedures
- →Vendor management: due diligence questionnaires, review schedules
Step 5 Evidence collection (the ongoing part)
Once your observation period starts, evidence collection runs continuously for 6–12 months. Manual evidence collection screenshots, spreadsheets, email chains is the old way. Modern compliance platforms connect directly to your cloud, identity, and dev tools to collect evidence automatically. This eliminates the pre-audit scramble and means your evidence room is always current.
Step 6 The audit
Find an AICPA-accredited CPA firm that specializes in SOC 2 audits. The audit process typically takes 4–8 weeks and involves document review, walkthroughs, and evidence testing. Your auditor will test a sample of evidence for each control. Exceptions (where evidence doesn't support the control) will need to be addressed or disclosed. The final SOC 2 report is typically ready 2–4 weeks after fieldwork completes.
Common failure points to avoid
After reviewing hundreds of SOC 2 audits, these are the controls companies most frequently fail on:
- →Access reviews: not running quarterly reviews of user access
- →Vendor reviews: not completing annual security reviews for critical vendors
- →Change management: missing approvals for emergency changes
- →Security training: employees not completing annual training
- →Incident response: not testing the IR plan with a tabletop exercise
Ready to automate this?
Avirio automates evidence collection, control testing, and audit management so you can focus on building.
Get a demo →