ISO & Compliance Implementation

SOC 2 Type II Readiness: The Trust Services Criteria Explained

“SOC 2 report” gets used loosely across sales calls and security questionnaires, but the Trust Services Criteria, the difference between Type I and Type II, and who actually performs the assessment are worth being precise about before you scope an engagement.

01

What SOC 2 actually is

An attestation report produced by an independent, licensed CPA firm, built on the AICPA’s Trust Services Criteria…

02

Type I vs Type II

Point-in-time design versus operating effectiveness over an observation period, and what each report actually contains…

03

Getting ready for an examination

Scope and criteria selection, gap assessment, remediation, and what’s actually changing on the standard-setting side…

What SOC 2 actually is

SOC 2 (System and Organization Controls 2) is an attestation report, not a certificate — it’s produced by an independent, licensed CPA firm, not issued by an accreditation body the way ISO 27001 certification is. It’s built on the AICPA’s Trust Services Criteria (TSC): Security is the mandatory baseline category for every SOC 2 report, often referred to as the “Common Criteria,” and four additional categories — Availability, Confidentiality, Processing Integrity, and Privacy — are selected based on what the service actually does and what customers are asking for, not applied as a blanket default. The TSC framework itself dates to 2017, with revised points of focus issued in 2022; that remains the current, applicable framework — there has been no newer version of the TSC itself.

Type I vs Type II

Type I assesses whether controls are suitably designed at a single point in time. Type II assesses whether those same controls actually operated effectively over an observation period, commonly three to twelve months. Most enterprise buyers specifically ask for Type II; Type I is sometimes used as an interim milestone while the Type II observation period runs. A SOC 2 report has a defined structure regardless of type: management’s assertion, the independent auditor’s opinion, and a description of the system — Type II reports add a detailed description of the tests of controls performed and their results, which is what lets a reader judge whether the controls actually held up, not just whether they were designed to.

STEP 01 Scope & Criteria Selection Which TSC categories actually apply STEP 02 Gap Assessment Against selected criteria STEP 03 Remediation & Evidence Continuous collection, not a scramble STEP 04 Observation Period (Type II) Evidence traces to the tested control
Most of the elapsed time sits in remediation and the observation period itself — not in scoping or the audit engagement.

Getting ready for an examination

Readiness work follows a predictable order: decide scope and which Trust Services Criteria categories actually apply before anything else, run a gap assessment against those criteria, remediate what the assessment finds, and stand up continuous evidence collection rather than scrambling to assemble screenshots the week before the audit starts. The observation period itself is where Type II lives or dies — evidence has to actually trace to the tested control across the full window, not just exist somewhere in a ticketing system. Many organizations run an internal readiness or mock assessment before the formal CPA engagement begins, specifically to catch gaps while they’re still cheap to fix.

What’s changing, and what isn’t: The AICPA’s Auditing Standards Board has an active, not-yet-finalized proposal to revise the baseline attestation standards (AT-C sections 105, 205, 210) that CPA firms follow when performing the audit itself — tightening evidence-quality and risk-assessment provisions. It does not change the Trust Services Criteria. The proposed effective date is for engagements beginning on or after June 15, 2029, and depends on the standard being finalized — it’s currently at the comment-letter stage, not final. Nothing changes for organizations today, but it’s a signal that evidence quality and traceability — logs, tickets, and reports that clearly trace to the tested control across the full observation period — will matter even more going forward.
Free download · PDF

Get the complete SOC 2 Type II Readiness Checklist

Seven checks covering scope, criteria selection and evidence, with a self-scoring sheet so you know what to fix first.

  • Printable checklist for your team and leadership
  • Scoring by section, so you know what to fix first
  • Option of a free 30-minute gap review with our practitioners

VVnT SeQuor · ISO 9001 & ISO 27001 certified · IAAP Organizational Member

Where should we send it?

All fields are required unless marked optional.

Enter your full name.

We'll email the PDF here.

Enter a valid email, like name@company.com.

Enter your company name.

Select your role.

When do you need to be compliant? (optional)

No spam. One-click unsubscribe.

Check your inbox

Your checklist is on its way to your email. If it hasn't arrived in 5 minutes, check your spam folder.

Want a second pair of eyes on your answers?

Book a free 30-minute gap review

Frequently asked questions

What exactly is SOC 2, and who performs the assessment?

SOC 2 is an attestation report built on the AICPA’s Trust Services Criteria, produced by an independent, licensed CPA firm — it is not a certificate issued by an accreditation body the way ISO 27001 certification is.

Which Trust Services Criteria do we actually need?

Security is mandatory for every SOC 2 report — it’s often called the Common Criteria. The other four categories (Availability, Confidentiality, Processing Integrity, and Privacy) are selected based on what your service actually does and what your customers are asking for, not applied as a blanket default.

Is anything about SOC 2 changing soon?

The Trust Services Criteria themselves aren’t changing. The AICPA’s Auditing Standards Board does have an active, not-yet-finalized proposal to revise the baseline attestation standards CPA firms follow when performing the audit, with a proposed effective date for engagements beginning on or after June 15, 2029 — it’s currently at the comment-letter stage, not final, so nothing changes for organizations today.