SOC 2 Type II: What Auditors Actually Look For
A Series B SaaS company closed a six-figure enterprise deal contingent on delivering a clean SOC 2 Type II report within 90 days. Their controls had been running for the required observation period. The audit firm began fieldwork. On day three, the auditor asked for evidence that terminated employees had access revoked within 24 hours per the company's own policy. Of the twelve terminations during the audit period, three showed access revoked at 72+ hours. One showed five days. The auditor noted exceptions for each, and the report shipped with qualifications. The enterprise buyer accepted it -- but required a remediation plan and a re-examination in six months. The company spent $40,000 on the second audit that should have been unnecessary.
SOC 2 is not a pass/fail exam. It is not a certification. It is an attestation -- a CPA firm's professional opinion on whether your controls operated effectively over a defined period. Understanding what auditors actually test, and preparing accordingly, is the difference between a clean report and a qualified one that raises more questions than it answers.
Why SOC 2 Type II Is a 2026 Revenue Gate
Three market dynamics are compressing SOC 2 timelines for growing companies.
First, enterprise procurement teams have standardized on requesting SOC 2 Type II reports as a security due diligence baseline. Not Type I (point-in-time design assessment) -- Type II (operational effectiveness over time). A Type I report used to satisfy early-stage buyers; that era is over for any deal above mid-five figures.
Second, cyber insurance underwriters are requesting SOC 2 reports as part of the renewal process. Companies without them face higher premiums or coverage exclusions for specific incident types. The report is becoming table stakes for the insurance market, not just the enterprise sales cycle.
Third, downstream vendor risk programs are tightening. If your customers are themselves subject to SOC 2, HIPAA, or FedRAMP, they need evidence that their supply chain is controlled. Your SOC 2 Type II report is that evidence.
Type II vs Type I: The Operational Difference
A SOC 2 Type I report evaluates whether your controls are suitably designed at a point in time. A Type II report evaluates whether those controls operated effectively over a period -- typically 6-12 months. Type II is what matters because it provides assurance that controls actually work in practice, not just on paper.
The examination is conducted by a CPA firm in accordance with AICPA standards (AT-C Section 205). The resulting report follows a standardized format, but the controls tested are specific to your organization. There is no universal SOC 2 controls list. You and your auditor agree on a controls matrix that reflects your environment, and the auditor tests against that matrix.
This is an important distinction: SOC 2 does not result in a certification. There is no "SOC 2 certified" status. The output is an auditor's report containing their professional opinion. A clean report with no exceptions is the goal -- but even a report with qualifications is a valid SOC 2 report.
The Five Trust Services Criteria
SOC 2 is built on five Trust Services Criteria (TSC). Security is always required. The other four are selected based on what your business does and what your customers care about:
| Criterion | Required? | What It Covers |
|---|---|---|
| Security (CC) | Always required | Protection against unauthorized access, both physical and logical |
| Availability (A) | Optional | System uptime, disaster recovery, performance monitoring |
| Processing Integrity (PI) | Optional | Data processed completely, accurately, and in a timely manner |
| Confidentiality (C) | Optional | Protection of information designated as confidential |
| Privacy (P) | Optional | Collection, use, retention, and disposal of personal information |
Most SaaS companies include Security and Availability. Companies handling sensitive data add Confidentiality. Companies processing personal data (especially those also subject to GDPR/CCPA obligations) add Privacy.
The Contrarian Take: Fewer Controls, Operated Perfectly, Beat More Controls Operated Inconsistently
Organizations preparing for SOC 2 frequently make the same mistake: they define an ambitious controls matrix with 120+ controls, then struggle to operate all of them consistently for twelve months. The result is a report riddled with exceptions.
Here is the hard-won lesson: auditors test what you commit to. If your policy says access is revoked within 24 hours, the auditor tests against 24 hours. If your policy said 72 hours, the three late revocations in the opening scenario would not have been exceptions. The optimal strategy is not maximal controls -- it is right-sized controls that your team can actually execute consistently, every time, for the full audit period. A 60-control matrix operated perfectly produces a cleaner report than a 120-control matrix with a dozen exceptions.
Define policies you can actually meet. Then meet them without exception for twelve months. That is the entire game.
What Auditors Actually Examine
Evidence Over Assertions
Auditors test controls by examining evidence, not by accepting management assertions. For each control, the auditor selects a sample and examines artifacts that prove the control operated as described:
| Control Area | Evidence Auditors Request |
|---|---|
| Access Control | Access configurations, user provisioning tickets, access review records |
| Change Management | Change request tickets, approval records, deployment logs, code review evidence |
| Monitoring | Alert configurations, incident tickets, dashboard screenshots, on-call schedules |
| Encryption | TLS configurations, key management procedures, certificate inventory |
| Vendor Management | Vendor risk assessments, SOC 2 reports from critical vendors, contract reviews |
| HR Security | Background check records, onboarding checklists, security training completion |
Sample Testing
For controls that operate frequently (daily, per-transaction), auditors select a sample and test whether each sample item shows the control operating correctly. A single exception in a sample of 25 may result in a qualified opinion for that control.
For controls that operate periodically (quarterly access reviews, annual penetration tests), auditors examine all instances during the audit period. If your annual penetration test was not completed during the audit period, that is an exception -- full stop.
Walkthroughs
Auditors conduct walkthroughs of key processes to understand how controls function end-to-end. They interview personnel, observe processes, and trace transactions through systems. The walkthrough is where auditors identify gaps between documented procedures and actual practice.
The Controls Matrix
Before the audit, you and your auditor agree on a controls matrix that maps your specific controls to the applicable Trust Services Criteria. This matrix becomes the scope of the examination.
A typical controls matrix includes 50-120 controls, depending on the scope and complexity of your environment. Each control must be:
- Described -- What the control does and how it operates
- Mapped to TSC -- Which Trust Services Criteria points it addresses
- Evidenced -- What artifacts demonstrate its effectiveness
- Tested -- How the auditor will verify it
Preparing for a Type II Audit
6+ Months Before
- Select your Trust Services Criteria scope
- Engage an audit firm and agree on the controls matrix
- Implement any controls that are not yet operational
- Begin the audit period (controls must operate for the full period)
During the Audit Period
- Operate controls consistently -- exceptions during this period become audit findings
- Collect evidence continuously -- do not wait until the audit to gather screenshots
- Complete all periodic activities on schedule (access reviews, pen tests, training)
- Document incidents and remediation actions
Audit Fieldwork
- Provide requested evidence promptly
- Make key personnel available for walkthroughs
- Address auditor questions with specifics, not generalities
- Prepare a management response for any identified exceptions
What Makes a Clean Report
A clean SOC 2 Type II report has no exceptions or qualifications. This requires:
- Consistency -- Controls operated the same way throughout the audit period
- Completeness -- All periodic activities were completed on schedule
- Documentation -- Evidence exists for every control instance tested
- No access violations -- Access provisioning and deprovisioning followed policy
- Timely incident response -- Incidents were handled per the documented IR plan
Common Exceptions
The most frequent SOC 2 exceptions:
- Delayed access revocation -- User access not removed within the policy-defined timeframe after termination
- Missing change approvals -- Code deployed to production without documented approval
- Incomplete access reviews -- Quarterly or semi-annual access reviews not performed or not documented
- Late security training -- Employees not completing security awareness training within the required window
- Missing vendor assessments -- Critical vendors not assessed during the audit period
Each exception does not necessarily result in a qualified opinion. The auditor evaluates whether the exception represents a systemic failure or an isolated incident. But even isolated exceptions land in the report -- and your customers read it.
SOC 2 and Other Frameworks
SOC 2 shares significant overlap with other compliance frameworks:
- ISO 27001 -- Both address information security management; many controls are equivalent
- HIPAA -- Technical safeguards overlap substantially with SOC 2 Security criteria
- FedRAMP -- FedRAMP controls map to many SOC 2 requirements
- NIST CSF -- The Cybersecurity Framework categories align with Trust Services Criteria
Organizations pursuing multiple frameworks should map controls once and apply them across all applicable standards using a multi-framework approach. A single access review that satisfies SOC 2, ISO 27001, and HIPAA simultaneously is one access review -- not three.
Key Takeaways
- SOC 2 is an attestation (auditor's opinion), not a certification -- there is no "SOC 2 certified" status.
- Type II tests operational effectiveness over 6-12 months; Type I only tests design at a point in time.
- Auditors test what you commit to -- right-size your policies to what your team can execute consistently.
- A single exception in a 25-item sample can qualify that control in the report.
- Continuous evidence collection throughout the audit period eliminates the pre-audit scramble.
Frequently Asked Questions
How long does the SOC 2 Type II audit period need to be?
The minimum observation period is typically 6 months, though 12 months is standard and preferred by most enterprise buyers reviewing your report. Shorter periods (3 months) are sometimes accepted for a company's first Type II report, but auditors and report readers generally view longer periods as more credible. The period must be continuous -- you cannot combine non-adjacent months.
How much does a SOC 2 Type II audit cost?
Costs range from $30,000 to $100,000+ depending on the scope (number of Trust Services Criteria), complexity of your environment, size of your controls matrix, and the audit firm. First-time audits tend toward the higher end because the firm invests more time understanding your environment. Subsequent annual examinations are typically less expensive if your environment has not changed significantly.
What is the difference between a SOC 2 report and ISO 27001?
SOC 2 is an attestation report produced by a CPA firm -- it describes your controls and the auditor's opinion on their effectiveness. ISO 27001 is a certifiable standard -- an accredited certification body audits your information security management system and issues a certificate valid for 3 years (with annual surveillance audits). SOC 2 is predominant in North America; ISO 27001 carries more weight internationally. Many organizations pursue both, and the control overlap is substantial.
Can we share our SOC 2 report with anyone who asks?
SOC 2 reports are restricted-use documents. The standard report is intended for existing customers, prospective customers under NDA, and regulators. You cannot post it publicly on your website. Some organizations produce a SOC 3 report (a general-use summary without detailed control descriptions) for public distribution. In practice, most companies share the full report under NDA with serious prospects during the sales process.
What if we get exceptions -- is the report useless?
No. A report with exceptions is still a valid SOC 2 Type II report. Most enterprise buyers evaluate the nature of exceptions, not just their presence. A single isolated exception in a non-critical control area (e.g., one late training completion) is very different from systemic exceptions across access management controls. The key is your management response: demonstrate that you identified the root cause, implemented corrective action, and can show the control operating correctly after the exception. Buyers who reject reports with any exceptions are rare -- but they exist, which is why prevention is always preferable to remediation.
How Advisedly Helps
Advisedly streamlines SOC 2 Type II readiness by continuously collecting evidence mapped to your controls matrix throughout the audit period. Instead of a scramble before audit fieldwork, the platform maintains a living evidence repository that captures access configurations, change records, and monitoring data as controls operate. The controls matrix builder maps your controls to the Trust Services Criteria and tracks readiness across all five categories. For organizations managing SOC 2 alongside other frameworks, the platform cross-maps controls across 500+ frameworks so a single access review satisfies SOC 2, ISO 27001, and HIPAA simultaneously. Contact begin@advisedly.ai to build your controls matrix and prepare for your next Type II audit.
<!-- LI hook: SOC 2 is not a certification. Here is what it actually is. -->