SOC 2 compliance
SOC 2 is the report enterprise security teams ask for before they trust a vendor with their data. If you sell software to businesses, someone will ask for it.
What is SOC 2
SOC 2 is an attestation report in which an independent auditor verifies that your security controls actually operate.
It applies to almost any B2B software company. There is no legal trigger; your customers' security teams are the enforcement mechanism.
What SOC 2 includes
Four categories of controls, plus the audit that verifies them. Scadable runs the controls, keeps the evidence current, and hands the auditor what they ask for.
How long it takes
These are Scadable timelines. A Type I report is a point-in-time snapshot. A Type II report, the one enterprise customers usually ask for, adds a 3-month observation window that starts as soon as your controls are running.
Controls verified over a 3-month observation window. What enterprise customers usually ask for.
Get SOC 2-ready. Without the busywork.
Frequently asked questions
- A Type I report checks that your controls are designed correctly at a single point in time. A Type II verifies they actually operated over an observation window of 3 to 12 months. Enterprise customers almost always want Type II.
- No. There is no law behind it. The pressure is contractual: enterprise security reviews ask for a SOC 2 report, and without one the deal stalls in procurement. In practice that makes it as mandatory as any regulation.
- Security is always in scope. The other four are added based on what you promise customers: uptime SLAs pull in Availability, handling sensitive business data pulls in Confidentiality. Most first reports cover Security alone or Security plus Availability.
- A Type II report covers a specific period, and customers expect a fresh one every year. That makes SOC 2 a continuous practice, not a one-time project: controls and evidence have to keep operating between audits.
- They overlap heavily in controls. SOC 2 is an attestation report favored by US customers; ISO 27001 is a certification favored internationally. If you sell in both markets you may end up doing both, and the shared evidence does double duty.
- No. A SOC 2 report contains detail about your systems and is shared under NDA, usually through a trust portal. The public-facing version is a SOC 3 report or a trust page summarizing your posture.
This page is educational information, not legal advice. Confirm your company's SOC 2 scope with a qualified auditor.
