SOC 2 is an attestation standard from the AICPA where an independent auditor examines how a service organization protects customer data, against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. For SaaS companies it has become the de facto ticket to enterprise deals: no report, no procurement approval.
Key facts:
- SOC 2 is an auditor's attestation report, not a certificate: the deliverable is a detailed report on your controls, shared with customers under NDA.
- Type I assesses control design at a point in time; Type II tests whether controls operated effectively over a period (typically 3 to 12 months). Enterprise buyers usually require Type II.
- Only the Security criteria (the Common Criteria) are mandatory; the other four categories are added by choice depending on the service.
- SOC 2 is voluntary and market-driven, unlike NIS2 and DORA which are law, but the control substance overlaps heavily.
The Trust Services Criteria
| Criterion | What it covers | Required? |
|---|---|---|
| Security | Protection against unauthorized access, logical and physical; the common criteria | Yes, in every SOC 2 report |
| Availability | Systems are available for operation and use as committed | Optional |
| Processing integrity | Processing is complete, valid, accurate, timely and authorized | Optional |
| Confidentiality | Information designated confidential is protected as agreed | Optional |
| Privacy | Personal information is collected, used, retained and disclosed per the privacy notice | Optional |
Type I vs Type II
Type I answers "are the right controls designed and in place today?" and can be produced quickly. Type II answers "did those controls actually operate for the whole audit period?" and is what serious buyers ask for, because it proves operation, not intention. The practical consequence: Type II requires continuous evidence (logs, alerts, reviews, incident records) collected throughout the period. Point-in-time screenshots do not survive a Type II audit; continuously monitored controls do.
The audit process
A typical path: choose scope (criteria and systems), run a readiness assessment against the Common Criteria, remediate gaps (this is where tooling, policies and processes get built), operate the controls while collecting evidence, then undergo the audit with an accredited CPA firm. Most first-timers go Type I then Type II, or straight to Type II with a shorter initial period.
Where email security fits, honestly
No product makes an organization SOC 2 attested; the audit covers your whole control environment. But several Common Criteria run straight through the mailbox, and this is where an email security layer carries real audit weight:
The incident chain deserves emphasis: auditors test not only that incidents are handled but that they are detected and documented in the first place. Detection you can show, with timestamps, scope and disposition, is the difference between an incident narrative and an incident record.
This page is general guidance, not legal or audit advice. Scope and evidence requirements are set with your auditor.