SOC 2 Compliance for Service Organizations
The attestation report enterprise buyers ask for before they’ll sign with a SaaS vendor, a B2B technology platform, or a technology service provider. Here’s what SOC 2 actually is, what it takes to get one, and how Armorstack builds the program around it.
A SOC 2 report (System and Organization Controls 2) is an attestation issued by an independent, licensed CPA firm under AICPA attestation standards (SSAE 18 / AT-C 205) on how a service organization’s controls measure up against the AICPA’s Trust Services Criteria. It is not a certification, not a pass/fail exam, and not something you can display as a badge without context — it is a detailed auditor’s opinion, typically shared with customers and prospects under NDA rather than published publicly.
Type I vs. Type II
Point-in-time design opinion
Confirms controls were suitably designed as of a single date. No testing of whether they operated over time. Can be issued in weeks once policies and controls are documented.
Operating-effectiveness opinion
Confirms design and that controls operated effectively across an observation window — the report most enterprise buyers actually require.
The Five Trust Services Criteria
Every SOC 2 report is scoped against the same five criteria. Only one is mandatory — the rest are selected based on what your service actually does.
Security Required
The Common Criteria (CC1–CC9): access control, change management, monitoring, and system operations. Every report includes it.
Availability
Systems are available for operation as committed — relevant to SaaS platforms with uptime SLAs.
Confidentiality
Information designated confidential is protected — common for fintech and B2B platforms handling client data.
Processing Integrity
Processing is complete, valid, accurate, and timely — relevant to payment and transaction-processing platforms.
Privacy
Personal information is collected, used, retained, and disposed of per commitments — relevant when consumer PII is in scope.
SaaS, B2B Technology, and Technology Service Providers
SOC 2 is the default trust artifact for any business that stores, processes, or has system access to another company’s data. Enterprise SaaS vendors need it before security review will pass; B2B platforms handling customer PII or financial data need it before procurement will sign; and technology service providers — especially those with standing remote access into client environments — increasingly need it because their own SOC 2 posture is a control point in every client’s audit chain. If your vendor risk questionnaire keeps asking “do you have a SOC 2 report,” you are already past the point where this is optional.
VERITY Governs the Program. SENTRY Provides the Evidence.
VERITY: Governance & Readiness
VERITY runs the gap assessment against your selected Trust Services Criteria, builds the policy set, assigns control owners, and manages the roadmap from readiness through Type I and into the Type II observation window. See how the readiness assessment works.
SENTRY: Continuous Monitoring Evidence
SENTRY’s managed detection and response generates the access logs, alerting records, and monitoring evidence that Type II auditors sample directly — produced as a byproduct of normal operations rather than assembled before an audit.
The Full SOC 2 Guide Series
Ready to Scope Your SOC 2 Program?
Talk to Armorstack about which Trust Services Criteria apply, whether Type I or Type II is the right starting point, and how fast a converged VERITY and SENTRY program can get you audit-ready.