SOC 2 Type II Readiness: The Trust Services Criteria Explained
“SOC 2 report” gets used loosely across sales calls and security questionnaires, but the Trust Services Criteria, the difference between Type I and Type II, and who actually performs the assessment are worth being precise about before you scope an engagement.
By VVnT SeQuor Team··3 min read
In this article
01
What SOC 2 actually is
An attestation report produced by an independent, licensed CPA firm, built on the AICPA’s Trust Services Criteria…
02
Type I vs Type II
Point-in-time design versus operating effectiveness over an observation period, and what each report actually contains…
03
Getting ready for an examination
Scope and criteria selection, gap assessment, remediation, and what’s actually changing on the standard-setting side…
What SOC 2 actually is
SOC 2 (System and Organization Controls 2) is an attestation report, not a certificate — it’s produced by an independent, licensed CPA firm, not issued by an accreditation body the way ISO 27001 certification is. It’s built on the AICPA’s Trust Services Criteria (TSC): Security is the mandatory baseline category for every SOC 2 report, often referred to as the “Common Criteria,” and four additional categories — Availability, Confidentiality, Processing Integrity, and Privacy — are selected based on what the service actually does and what customers are asking for, not applied as a blanket default. The TSC framework itself dates to 2017, with revised points of focus issued in 2022; that remains the current, applicable framework — there has been no newer version of the TSC itself.
Type I vs Type II
Type I assesses whether controls are suitably designed at a single point in time. Type II assesses whether those same controls actually operated effectively over an observation period, commonly three to twelve months. Most enterprise buyers specifically ask for Type II; Type I is sometimes used as an interim milestone while the Type II observation period runs. A SOC 2 report has a defined structure regardless of type: management’s assertion, the independent auditor’s opinion, and a description of the system — Type II reports add a detailed description of the tests of controls performed and their results, which is what lets a reader judge whether the controls actually held up, not just whether they were designed to.
Most of the elapsed time sits in remediation and the observation period itself — not in scoping or the audit engagement.
Getting ready for an examination
Readiness work follows a predictable order: decide scope and which Trust Services Criteria categories actually apply before anything else, run a gap assessment against those criteria, remediate what the assessment finds, and stand up continuous evidence collection rather than scrambling to assemble screenshots the week before the audit starts. The observation period itself is where Type II lives or dies — evidence has to actually trace to the tested control across the full window, not just exist somewhere in a ticketing system. Many organizations run an internal readiness or mock assessment before the formal CPA engagement begins, specifically to catch gaps while they’re still cheap to fix.
What’s changing, and what isn’t: The AICPA’s Auditing Standards Board has an active, not-yet-finalized proposal to revise the baseline attestation standards (AT-C sections 105, 205, 210) that CPA firms follow when performing the audit itself — tightening evidence-quality and risk-assessment provisions. It does not change the Trust Services Criteria. The proposed effective date is for engagements beginning on or after June 15, 2029, and depends on the standard being finalized — it’s currently at the comment-letter stage, not final. Nothing changes for organizations today, but it’s a signal that evidence quality and traceability — logs, tickets, and reports that clearly trace to the tested control across the full observation period — will matter even more going forward.
Free download · PDF
Get the complete SOC 2 Type II Readiness Checklist
Seven checks covering scope, criteria selection and evidence, with a self-scoring sheet so you know what to fix first.
Printable checklist for your team and leadership
Scoring by section, so you know what to fix first
Option of a free 30-minute gap review with our practitioners
VVnT SeQuor · ISO 9001 & ISO 27001 certified · IAAP Organizational Member
Check your inbox
Your checklist is on its way to your email. If it hasn't arrived in 5 minutes, check your spam folder.
What exactly is SOC 2, and who performs the assessment?
SOC 2 is an attestation report built on the AICPA’s Trust Services Criteria, produced by an independent, licensed CPA firm — it is not a certificate issued by an accreditation body the way ISO 27001 certification is.
Which Trust Services Criteria do we actually need?
Security is mandatory for every SOC 2 report — it’s often called the Common Criteria. The other four categories (Availability, Confidentiality, Processing Integrity, and Privacy) are selected based on what your service actually does and what your customers are asking for, not applied as a blanket default.
Is anything about SOC 2 changing soon?
The Trust Services Criteria themselves aren’t changing. The AICPA’s Auditing Standards Board does have an active, not-yet-finalized proposal to revise the baseline attestation standards CPA firms follow when performing the audit, with a proposed effective date for engagements beginning on or after June 15, 2029 — it’s currently at the comment-letter stage, not final, so nothing changes for organizations today.
This is general guidance, not a scoped engagement plan. If you want one for your specific environment, talk to our ISO & Compliance Implementation practice.