← Back to blog

SOC 2 Compliance Requirements: Your 2026 Guide

July 20, 2026
SOC 2 Compliance Requirements: Your 2026 Guide

TL;DR:

  • SOC 2 compliance involves implementing controls across Trust Services Criteria, with security being mandatory. Type 2 audits, covering six to twelve months, demonstrate ongoing controls effectiveness crucial for enterprise trust. Preparing successfully requires continuous evidence collection, narrow initial scope, and integrating controls into daily operations.

SOC 2 compliance requirements are defined by the American Institute of Certified Public Accountants (AICPA) as the controls service organizations must implement to protect customer data across five Trust Services Criteria. Security is the only mandatory criterion. The remaining four — Availability, Processing Integrity, Confidentiality, and Privacy — are optional and selected based on your services and client contracts. SOC 2 is voluntary but effectively mandatory for tech and finance firms, since enterprise procurement teams now require it as a baseline trust signal. Audits follow AICPA SSAE 18 standards and produce either a Type 1 or Type 2 report, with Type 2 covering a 6–12 month observation window.

What are the SOC 2 compliance requirements and Trust Services Criteria?

The Trust Services Criteria (TSC) are the foundation of every SOC 2 audit. They define what controls your organization must design, implement, and demonstrate. Security is the only required criterion, and it contains about 64 underlying controls organized across nine Common Criteria categories (CC1 through CC9). That scope covers your control environment, risk assessment, communication practices, logical access, and monitoring activities.

The four optional criteria each address a distinct risk area:

  • Availability: Controls that keep your systems accessible per agreed service levels, including uptime monitoring, incident response, and disaster recovery procedures.
  • Processing Integrity: Controls that verify your system processes data completely, accurately, and on time. This criterion applies most directly to financial processing and transaction platforms.
  • Confidentiality: Controls protecting data designated as confidential, such as encryption at rest and in transit, data classification policies, and access restrictions.
  • Privacy: Controls governing the collection, use, retention, and disposal of personal information, aligned with frameworks like NIST Privacy Framework and GDPR principles.

Criteria selection directly shapes your audit scope, cost, and timeline. Over-scoping by adding unnecessary criteria increases costs and audit duration without proportional value. A SaaS billing platform serving enterprise clients will likely need Security and Confidentiality. A healthcare data processor may also need Privacy. A cloud infrastructure provider may add Availability. The right scope reflects your actual service commitments, not a desire to appear thorough.

Pro Tip: Map each optional criterion to a specific client contract requirement or regulatory obligation before including it. If no contract demands it, leave it out of your first audit.

Team discussing SOC 2 audit scope at table

Logical and physical access controls under CC6 frequently require the most remediation investment. Data loss prevention and identity management tools are often needed to satisfy auditor rigor at this level. Plan for that investment early.

Infographic illustrating SOC 2 Trust Services Criteria

How do SOC 2 Type 1 and Type 2 reports differ?

The two SOC 2 report types answer different questions. A Type 1 report asks: "Are your controls designed correctly as of today?" A Type 2 report asks: "Did your controls actually work over the past 6–12 months?" That distinction matters enormously to enterprise clients evaluating your security posture.

Type 1 evaluates controls at a single point in time and is faster to obtain. Organizations typically use it to demonstrate initial compliance readiness or to satisfy an urgent client request. Type 1 is a starting point, not a destination. Type 2 reports demonstrating operating effectiveness over time are what most enterprise clients expect for ongoing vendor relationships.

DimensionType 1Type 2
Assessment focusControl design at a point in timeControl effectiveness over an observation period
Observation windowNone (single date)6–12 months minimum
Audit effortLowerHigher
Client valueInitial trust signalContinuous compliance standard
Typical use caseFirst audit or urgent client needAnnual renewal and enterprise procurement

SOC 2 reports are generally valid for 12 months, after which you need a new audit. Only licensed CPA firms authorized by the AICPA can perform these audits. Auditor independence is non-negotiable. Your auditor cannot also be your compliance consultant for the same engagement.

Pro Tip: If you are pursuing SOC 2 for the first time, consider a Type 1 audit to identify control gaps, then move directly into a Type 2 observation window. This approach avoids paying for a Type 2 audit before your controls are mature.

For a deeper breakdown of how these two report types affect your vendor relationships, the Type 1 vs. Type 2 comparison from Skypher covers the practical differences in detail.

What documentation and evidence are required for SOC 2?

Documentation is where most organizations underestimate the work. Auditors do not simply review your security tools. They request evidence that your controls operated consistently across the entire observation period. Lack of continuous logs or incomplete evidence leads to audit failure independently of your underlying security posture.

The core documentation package includes:

  • System description: A narrative explaining your system boundaries, infrastructure, data flows, and the services in scope. This document defines what the auditor evaluates.
  • Management assertion: A signed statement from leadership confirming the system description is accurate and controls are in place.
  • Control matrix: A mapping of your policies and procedures to each applicable Trust Services Criterion, showing which controls address which requirements.
  • Access logs: Records of who accessed what systems, when, and with what permissions. These must cover the full observation window without gaps.
  • Incident records: Documentation of security events, how they were detected, how they were escalated, and how they were resolved.
  • Training records: Evidence that staff completed security awareness training during the observation period.
  • Vendor management documentation: Data processing agreements (DPAs), security posture reviews of subprocessors, and records of third-party risk assessments are also required by auditors.

Auditors sample evidence retrospectively across the observation window. Your internal systems must log and retain data consistently from day one of the period. A gap in access logs from a two-week period three months before your audit is a finding, not a footnote. Build your evidence collection infrastructure before the observation window opens, not after.

What are the best practices for achieving and maintaining SOC 2?

The most effective preparation strategy starts narrow and expands deliberately. Most organizations begin with Security-only scope to reduce audit complexity and build control maturity before adding additional criteria. Attempting to cover all five Trust Services Criteria in a first audit increases complexity and raises the risk of audit findings.

A proven preparation sequence looks like this:

  1. Conduct a gap assessment. Compare your current controls against the nine Common Criteria categories. Identify what is missing, what is partially implemented, and what needs documentation.
  2. Remediate gaps before the observation window opens. Controls must be in place and operating before the audit period begins. Fixing a control mid-window does not erase the gap that existed before.
  3. Implement continuous evidence collection. Set up automated logging for access events, system changes, and security incidents. Manual evidence collection fails at scale and introduces gaps.
  4. Schedule periodic control reviews. Quarterly access reviews, annual penetration tests, and regular vendor risk assessments are not optional. They are the evidence your auditor will request.
  5. Train your staff and document it. Security awareness training records are a standard auditor request. Run training at onboarding and annually, and retain the completion records.

Automation tools that continuously collect evidence and monitor controls reduce audit preparation time significantly and improve control effectiveness. Manual spreadsheet tracking breaks down during a 12-month observation window.

The most common pitfalls are predictable. Incomplete access reviews leave orphaned accounts that auditors flag immediately. Missing incident response exercises mean you cannot demonstrate your response process worked. Vendor oversight gaps, particularly with subprocessors handling customer data, create findings that reflect poorly on your entire security program.

Pro Tip: Treat your SOC 2 observation window like a live audit from day one. If you would not want an auditor to see a gap in your logs today, close it today.

For teams in tech and finance, the 2026 SOC 2 compliance guide from Skypher covers industry-specific control expectations in detail. You can also use a structured audit checklist to verify your evidence collection covers every required control category before your auditor arrives.

Key Takeaways

SOC 2 compliance requires implementing and evidencing effective controls across the mandatory Security criterion and any optional criteria your services demand, with Type 2 audits covering a 6–12 month observation window as the enterprise standard.

PointDetails
Security is mandatoryThe Security criterion contains about 64 controls across nine Common Criteria categories and applies to every SOC 2 audit.
Scope your criteria carefullyAdding optional criteria increases cost and complexity; select only those tied to actual client or regulatory requirements.
Type 2 is the enterprise standardType 2 reports demonstrate operating effectiveness over 6–12 months and are expected by most enterprise procurement teams.
Evidence must be continuousAuditors sample retrospectively, so logs, access records, and incident documentation must cover the full observation window without gaps.
Start narrow, then expandBegin with Security-only scope to build control maturity before adding Availability, Confidentiality, or other criteria in later audits.

SOC 2 is a security program, not a paperwork exercise

I have worked with compliance teams across tech and finance who treat SOC 2 as a documentation project. They spend months writing policies, then scramble to find evidence that those policies were actually followed. That approach fails, and it fails expensively.

The organizations that pass Type 2 audits cleanly are the ones that built their controls first and collected evidence as a byproduct of normal operations. Their access reviews happen on schedule because someone owns the calendar invite. Their incident records are complete because the ticketing system captures everything automatically. Their vendor risk assessments exist because procurement requires them before any new subprocessor goes live.

SOC 2 should be seen as a framework that encourages ongoing security culture, not a compliance checkbox. That framing changes how your team behaves during the observation window. When people understand that the audit is measuring real security behavior, they stop treating controls as theater.

The other mistake I see frequently is over-scoping on the first audit. Adding Privacy and Processing Integrity before your Security controls are mature is a recipe for findings across every criterion. Earn your Type 2 with Security first. Then expand. Your clients will respect the discipline more than the breadth.

— Gaspard

How Skypher supports your SOC 2 audit readiness

Regulated industries face a specific challenge during SOC 2 audits: clients and auditors both want proof of your security posture, and they want it fast.

https://skypher.co

Skypher's Trust Center platform centralizes your compliance documentation and security posture in one place, making it accessible to auditors and enterprise clients without manual back-and-forth. The platform's AI-powered tools automate security questionnaire responses, pulling from your existing control documentation to answer even complex reviews accurately. Skypher integrates with over 40 third-party risk management platforms, including OneTrust and ServiceNow, and connects directly with Slack, Microsoft Teams, Confluence, and SharePoint. For teams managing multiple products or entities, Skypher handles complex enterprise setups with multilingual support. Explore the Skypher Trust Center to see how it fits your compliance workflow.

FAQ

What is the minimum observation period for a SOC 2 Type 2 audit?

The minimum recommended observation period for a first-time SOC 2 Type 2 audit is six months. Reports are generally valid for 12 months, after which organizations need a new audit.

Is SOC 2 legally required?

SOC 2 is not a legal mandate. It is a voluntary attestation standard developed by the AICPA, but enterprise procurement teams in tech and finance increasingly require it as a condition of vendor contracts.

How many controls does SOC 2 require?

The mandatory Security criterion contains about 64 underlying controls. Organizations that add optional criteria can reach approximately 92 total control points across all five Trust Services Criteria.

Who can perform a SOC 2 audit?

Only licensed CPA firms authorized by the AICPA can issue SOC 2 reports. Auditor independence is required, meaning your auditor cannot also serve as your compliance consultant for the same engagement.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses whether controls are designed correctly at a single point in time. A Type 2 report evaluates whether those controls operated effectively over a 6–12 month observation period, which is the standard most enterprise clients require.