SOC 2 is not a certification you pass or fail — it's an auditor's opinion, attached to a report, on whether your controls actually operated the way you say they do. That distinction trips up a lot of first-time SaaS founders who expect a checklist with a pass/fail gate at the end. What you get instead is a report a prospect's security team reads closely, and the quality of that report depends entirely on how honestly the controls were designed and how consistently they were followed during the audit period.
Type I vs Type II
A Type I report assesses whether your controls are suitably designed as of a single point in time — it's a snapshot: here's what we say we do, and an auditor confirms the design makes sense. A Type II report assesses whether those controls actually operated effectively over an observation period, typically three to twelve months. Type II is materially harder to get and materially more valuable to a customer, because it proves the control wasn't just written down for the audit — it was followed for months, with evidence to show for it. Most enterprise buyers today expect Type II; a Type I report is increasingly treated as a placeholder while a company works toward the real thing.
Many companies do a Type I audit first to catch control-design gaps cheaply, then roll straight into the Type II observation period. Skipping Type I doesn't save time if it means discovering a broken control three months into a Type II window.
The trust service criteria
SOC 2 is built on five Trust Service Criteria, but only Security (also called the Common Criteria) is mandatory — Availability, Processing Integrity, Confidentiality, and Privacy are optional and scoped in based on what your product and customers actually need. Most SaaS companies scope in Security and Availability at minimum; Confidentiality matters more if you handle sensitive customer data beyond what's needed to run the product; Privacy is its own heavy lift and usually only scoped in if it's a specific customer requirement. Scoping in criteria you don't need just adds audit cost and evidence burden without adding sales value — talk to the customers actually asking for SOC 2 before deciding what to include.
Common controls auditors actually test
Auditors sample evidence rather than reviewing everything, but the categories are predictable: access control (unique logins, MFA, access reviews on a schedule, offboarding that actually revokes access same-day), change management (code review before merge, a documented deploy process, no direct production database access without a ticket), vendor management (a list of subprocessors and evidence you've assessed their risk), incident response (a written plan, and ideally evidence you've actually run a tabletop exercise), and monitoring (centralized logging, alerting on anomalous access, backup testing). The single most common finding in a first-time audit is access review: companies that say they review access quarterly but have no evidence — no ticket, no signed-off spreadsheet, nothing — that the review actually happened on schedule.
Doing the right thing informally doesn't satisfy a Type II audit. If you review access quarterly but don't log who reviewed what and when, the auditor has nothing to sample — and an unevidenced control is treated the same as a missing one.
A realistic timeline
A first-time SOC 2 Type II typically runs six to twelve months end to end: one to two months for a readiness assessment and gap remediation (this is usually where the real work is — writing policies that reflect what you actually do, fixing access-review processes, standing up centralized logging), then a three-to-twelve-month observation window where the auditor is watching controls operate, followed by four to eight weeks for the auditor to compile and issue the final report. Companies racing to close an enterprise deal often compress the observation window to three months for the first report, then extend to a full twelve-month window on the following year's audit once controls have matured.
Picking an auditor and a compliance platform
Compliance automation platforms (the well-known names in this space handle continuous evidence collection, policy templates, and auditor coordination) meaningfully reduce the manual burden of evidence gathering, but they don't replace the actual work of having real controls — they just make proving you have them less painful. The auditor itself matters: a CPA firm with genuine SaaS and cloud-infrastructure experience will ask sharper, more relevant questions than a generalist firm, and prospects reviewing your report sometimes recognize (and trust) certain audit firms more than others.
Wrapping up
SOC 2 Type II is worth more than Type I because it proves controls were followed, not just designed — and the report is only as strong as the evidence behind it. Budget six to twelve months for a first audit, scope in only the trust service criteria your customers actually require, and treat unevidenced controls as equivalent to missing ones, because that's exactly how the auditor will treat them.
Independent software engineer in Nairobi specialising in Acumatica customisations, Laravel backends, and tax fiscalisation integrations across East and Southern Africa.