Answers

What is SOC 2 in sales?

This page explains the SOC 2 mechanics that touch a revenue team day to day: the two report types, the five Trust Services Criteria, the compliance platforms sellers use to get there, and how SOC 2 shows up inside a procurement cycle. It is a general-purpose explanation, not audit or legal advice.

Short answer

SOC 2 is an audit standard from the American Institute of Certified Public Accountants (AICPA) that reports on how a vendor handles customer data against five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Type I reports describe controls at a single point in time; Type II reports verify those controls operated effectively over an observation window of six to twelve months. In B2B sales, a current SOC 2 report is the artifact enterprise buyers demand before signing, and it is now the single most common gating item in a security review.

Key points

What matters most.

Six things every revenue leader should know about SOC 2 before pitching an enterprise prospect, answering a procurement review, or routing a vendor evaluation internally.

What it is

An AICPA attestation report.

SOC 2 (System and Organization Controls 2) is an attestation report issued by an independent CPA firm under standards set by the American Institute of Certified Public Accountants. It describes the controls a service organization has in place to protect customer data and reports whether those controls meet the AICPA Trust Services Criteria. It is not a certification you buy; it is an audit you pass.

Two report types

Type I is a snapshot, Type II is a movie.

A Type I report describes and tests controls at one point in time. A Type II report observes those same controls operating across a window, usually six to twelve months, with evidence sampled throughout. Enterprise buyers almost always ask for Type II; Type I is treated as an interim artifact that proves a program exists.

Five criteria

Trust Services Criteria define scope.

Security is mandatory for every SOC 2. Availability, Processing Integrity, Confidentiality, and Privacy are optional and scoped based on what the service does. A CRM typically includes Security, Availability, and Confidentiality at minimum; Processing Integrity and Privacy show up when the system touches financial calculations or regulated personal data.

The sales artifact

A gating item in every enterprise deal.

In B2B sales, a current SOC 2 report under NDA is the artifact that unlocks a procurement review. It is attached to a security questionnaire, routed to the buyer's security and compliance teams, and reviewed line by line against the buyer's internal control framework. A missing or expired report stalls the deal immediately.

The platforms

Vanta, Drata, and Secureframe automate.

Compliance-automation platforms like Vanta, Drata, and Secureframe collect evidence continuously from a vendor's cloud providers, HR systems, and ticketing tools, then package it for the CPA auditor. They cut audit prep from months of spreadsheets to a continuously maintained program. Most SOC 2 reports issued today pass through one of these platforms.

Observation period

Type II takes time, not just money.

A Type II report cannot be purchased in a hurry. The report observes real control operation over a window that is typically six to twelve months, so a startup that decides to pursue SOC 2 in January is realistically looking at an initial Type II issued in the back half of the year, with a Type I available as an interim artifact in the meantime.

The two report types

Type I versus Type II, in practice.

SOC 2 is one standard with two very different artifacts. The difference between Type I and Type II is not cosmetic; it changes what the report actually proves, what it costs to produce, how long it takes, and how it is weighed by an enterprise buyer in procurement. A revenue leader who confuses the two will mis-sell the state of the compliance program and get caught in the first serious vendor review. Understanding the shape of each report is the baseline.

Type I design

Controls exist on a given date.

A Type I report describes the service organization's system and tests whether the controls are suitably designed as of a specific date. The auditor confirms that the policies, procedures, and technical controls exist and would be effective if operated. It is a snapshot. It says nothing about whether anyone actually followed those controls last Tuesday.

Type II operation

Controls worked over a window.

A Type II report tests the same controls, plus their operating effectiveness across an observation period, usually six to twelve months. The auditor samples evidence throughout the window: access reviews, change tickets, log retention, incident response records. A Type II report is substantially harder to earn and substantially more trusted.

Buyer preference

Enterprise wants Type II.

Enterprise procurement treats Type II as the real artifact. Type I is accepted as an interim signal from an early-stage vendor, usually with a commitment to produce a Type II within the next observation window. Expect pushback from any serious buyer who is handed a Type I without a Type II roadmap attached.

Report currency

Reports expire in practice.

SOC 2 reports do not technically expire, but buyers treat anything older than twelve to fifteen months with suspicion. Programs run on an annual observation cycle so that a current report is always available. A gap between reports (the bridge letter window) is normal, and auditors issue bridge letters to cover it.

Cost shape

Type II costs more than Type I.

Type I audits are smaller in scope and cheaper. Type II requires the observation window, more evidence collection, more sampling, and more auditor hours. The audit fee is only part of the cost; the full program includes internal time, the compliance-automation platform, security tooling, and remediation work before the audit begins.

First-time timeline

Plan six to twelve months.

A first-time SOC 2 Type II is a six-to-twelve-month project before the auditor opinion lands. The observation window itself is six months at minimum (sometimes three for an initial report), plus pre-audit remediation and post-fieldwork drafting. Buyers who ask for a Type II in three weeks are asking for something that does not exist.

The five criteria

Trust Services Criteria, scoped to the service.

SOC 2 reports are not one-size-fits-all. The AICPA defines five Trust Services Criteria, and the service organization chooses which ones are in scope based on what the service actually does. Security is mandatory for every SOC 2. The other four are optional, and the choice shapes the audit, the report, and the way an enterprise buyer evaluates the vendor. A CRM, a payroll service, and a backup provider will each pick a different combination.

Security

Mandatory for every SOC 2.

Also called the Common Criteria, Security is required in every SOC 2 report. It covers the controls that protect information and systems against unauthorized access, use, or modification: access management, encryption, change management, incident response, risk assessment, vendor management, and the full set of baseline security practices.

Availability

The service is up when promised.

Availability covers whether the system meets its operational and availability commitments: capacity planning, environmental protections, backup and recovery, incident handling, and monitoring. Any service with an SLA on uptime (which is every real CRM) should include Availability in scope. Enterprise buyers routinely insist on it.

Confidentiality

Confidential data stays confidential.

Confidentiality covers protection of information designated as confidential, including customer data that is not personal data. For a B2B CRM, this is the criterion that assures a buyer their pipeline, contact graph, and competitive intelligence will not leak. Access controls, encryption, data classification, and secure disposal all show up here.

Processing Integrity

Numbers in equal numbers out.

Processing Integrity covers whether system processing is complete, valid, accurate, timely, and authorized. Most relevant for services that calculate financial or regulatory outputs: billing, payroll, trading, reporting. A core CRM usually does not need Processing Integrity in scope; a billing or revenue-recognition module might.

Privacy

Personal information handled properly.

Privacy covers how personal information is collected, used, retained, disclosed, and disposed of, mapped against the AICPA Generally Accepted Privacy Principles. It overlaps with GDPR, CCPA, and other privacy regimes but is scored against the AICPA framework. Vendors handling consumer or regulated personal data at scale often include Privacy; a pure B2B CRM may defer it.

Scope decisions

Pick what the service actually does.

The scoping choice is driven by the service, the data it touches, and the commitments it makes to customers. Buyers will push back if a report excludes a criterion that obviously applies: a backup service without Availability, a payment calculator without Processing Integrity, or a people-data platform without Privacy. The report preface explains the scoping choice and auditors review it.

The sales workflow

How SOC 2 shows up in a real deal.

A SOC 2 report does not sit in a drawer. It moves through the sales cycle as a structured artifact, and the sales team that knows how to route, position, and defend it closes faster than the one that treats it as an afterthought. Most enterprise deals touch SOC 2 at four or five specific moments between first conversation and signature. Understanding the choreography is as important for a seller as understanding pricing or the ICP.

Trust page

The report lives behind an NDA.

SOC 2 reports contain sensitive details about a vendor's internal controls and are never public. They are hosted on a trust center (a dedicated page or portal) and released under NDA to prospects who need them. Many vendors use a trust-page product so prospects can self-serve the NDA and the report in minutes, which keeps the deal moving.

Questionnaire

Attached to the security review.

The SOC 2 report is almost always attached to a longer security questionnaire (CAIQ, SIG, or a buyer's custom template). The questionnaire has fifty to five hundred questions that the vendor answers against the report plus other evidence. A current Type II report cuts the questionnaire time down because many answers point directly to the audited control.

Procurement review

Security team reads it line by line.

The buyer's security or GRC function will read the SOC 2 report line by line, especially the exceptions section at the end. An exception is a finding where the control did not operate as described. A clean report with no exceptions is best; a few exceptions with documented remediation is acceptable; a long exceptions list is a deal risk.

MSA language

SOC 2 clauses in the contract.

A buyer's master services agreement will usually require the vendor to maintain SOC 2 Type II continuously, provide the latest report on request, and notify the buyer of material exceptions or lapses. The sales team should know these clauses are coming and route them to the right internal owner (usually security or legal) early rather than at redlines.

Subprocessors

The report must cover vendors too.

SOC 2 scope has to include the subprocessors that the service relies on: cloud infrastructure, email, enrichment, analytics. Either the vendor's own controls over those subprocessors are tested, or the subprocessor's own SOC 2 is relied upon under the AICPA carve-out or inclusive methods. The subprocessor list in the report matters as much as the control list.

Annual refresh

A new report every year.

Enterprise customers expect a fresh SOC 2 Type II every year, usually accompanied by a bridge letter covering any gap. Account management teams are responsible for distributing the new report to the installed base once it lands, and sales teams should know when the next report is expected so they can time deals or set a specific delivery date in the MSA.

A CRM that already lives inside a published trust program.

Strkr runs on audited cloud infrastructure, publishes its own trust materials, and integrates cleanly with the compliance-automation platforms your prospects already use. See the public pricing and the feature pages before your next security review.

People also ask

Related questions.

Do I actually need SOC 2 to sell to enterprise B2B?

In most cases yes. A current SOC 2 Type II is the single most common gating artifact in enterprise B2B procurement, and buyers in regulated industries (finance, healthcare, government contracting, and most of the Fortune 1000) treat it as mandatory. There are workarounds for very early-stage vendors (Type I reports, in-progress attestations, compensating controls documented in a questionnaire) but they slow the deal and shrink the addressable market. If the ICP includes enterprise, SOC 2 Type II is a baseline investment, not an optional one.

What is the difference between SOC 1, SOC 2, and SOC 3?

All three are AICPA reports. SOC 1 covers controls relevant to financial reporting (payroll, billing, invoicing, revenue recognition); it is read by the customer's financial auditors. SOC 2 covers controls over security, availability, processing integrity, confidentiality, and privacy of customer data; it is read by the customer's security and compliance teams. SOC 3 is a shorter, public-facing summary of a SOC 2 report that can be shared without an NDA. Most SaaS vendors issue a SOC 2 Type II and sometimes a companion SOC 3 for marketing use.

How long does it take to get a first SOC 2 Type II?

A realistic first-time Type II takes six to twelve months from program kickoff to issued report. The observation window itself is typically six months (sometimes three for an initial report, which is unusual), plus two to four months of pre-audit preparation (writing policies, implementing controls, remediating gaps) and a few weeks of fieldwork and drafting after the window closes. A Type I report can be issued in two or three months and is often used as an interim artifact while the Type II window runs.

What does a SOC 2 audit actually cost?

Costs vary widely. The audit fee itself for a Type II from a mid-tier CPA firm commonly lands in the mid five figures for a first-year report at a small SaaS vendor, with larger scopes and bigger firms running higher. The full program cost (compliance-automation platform subscription, security tooling, internal time, remediation work, and audit fee combined) is usually a multiple of the raw audit fee. Public estimates vary and a vendor's own quotes from auditors and automation platforms are the honest answer.

Which Trust Services Criteria should a CRM include?

A B2B CRM typically includes Security (mandatory), Availability, and Confidentiality at minimum. Availability covers the uptime commitment, and Confidentiality covers the customer data that is not personal data (pipeline records, deal history, competitive notes). Processing Integrity shows up when the CRM calculates billing, revenue, or regulated outputs. Privacy is added when the vendor processes consumer or regulated personal data at scale and wants to publish an AICPA-aligned privacy report rather than relying solely on GDPR or CCPA documentation.

What is a bridge letter and when is one needed?

A bridge letter is a short attestation from the vendor that covers the gap between the end of one SOC 2 observation window and the issuance of the next report. It states that no material changes have occurred to the control environment since the last audit. Enterprise buyers routinely ask for a bridge letter when the current SOC 2 report is six to nine months old. The auditor usually provides a template; the vendor signs it and distributes it on request alongside the most recent report.

Can Vanta, Drata, or Secureframe issue a SOC 2 report?

No. Only a licensed CPA firm can issue a SOC 2 attestation report under AICPA standards. Compliance-automation platforms like Vanta, Drata, and Secureframe do not perform the audit; they collect, organize, and continuously monitor the evidence that a CPA firm then uses to perform the audit. Most of these platforms partner with a network of audit firms and can introduce a vendor to one. The report itself always comes from the CPA firm, on CPA firm letterhead, signed by the auditor.

Is a SOC 2 report enough to pass a security review?

Usually not on its own, but it is the biggest single artifact. A full enterprise security review will combine the SOC 2 report with a completed security questionnaire, a DPA (where personal data is involved), a public privacy policy, a subprocessor list, a published trust page, penetration test summaries, business continuity documentation, and sometimes a CAIQ or SIG Lite response. The SOC 2 report accelerates the review by letting the vendor point to audited controls instead of writing fresh prose for every question, but the surrounding artifacts still have to be in place.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.