
SOC 2
SOC 2
Not a certificate on the wall. A report your customers’ auditors actually read.
An attestation that your controls match the Trust Services Criteria.
Who it's for. SaaS and service companies that hear “send us your SOC 2” on every enterprise deal.
01
The five criteria
Official-ish
Security (required), plus optional Availability, Confidentiality, Processing Integrity, and Privacy.
Monday version
Security is the door. Availability is uptime promises. Confidentiality is “we meant to keep this secret.” Processing Integrity is “the numbers are right.” Privacy is personal data done properly.
Do this
- Pick extra criteria only if customers pay you for those promises.
- Map each criterion to controls you can evidence weekly, not annually.
- Do not claim Privacy if you only meant “we have a cookie banner.”
02
Type I vs Type II
Official-ish
Type I: controls designed at a point in time. Type II: controls operated over a period (often 3–12 months).
Monday version
Type I is a snapshot. Type II is “did you actually do the access reviews for six months?” Buyers want Type II.
Do this
- Start collecting evidence the day you say you are “going through SOC 2.”
- Automate screenshots you are tired of taking (access, backups, alerts).
- Treat exceptions as stories with tickets, not as hope they go unnoticed.
03
What auditors poke
Official-ish
Common criteria cover control environment, communication, risk, monitoring, and logical/physical access, change, and operations.
Monday version
Onboarding/offboarding, change tickets, prod access, incident records, vendor reviews. If it is not written, it did not happen.
Do this
- Kill leftover accounts the week someone leaves — then keep the ticket.
- Separate who writes code from who pushes prod, or document the compensating control.
- Read your own report’s exceptions before a customer does.
Friendly translation, not legal advice. Always read the official text before you tell an auditor you “basically already do this.”