What should you do if a customer asks for your SOC 2 report?
You are about to close a contract with a US customer or an international enterprise – and during the security review, the question comes up: "Can you provide us with your current SOC 2 report?"
For many SaaS and cloud companies, this is the point where SOC 2 becomes concretely relevant for the first time. This request is not unusual in international B2B business. Larger companies, in particular, use SOC 2 reports to evaluate the security and control processes of their service providers. If you do not yet have a SOC 2 report, it does not automatically mean the deal is lost. However, it does mean you should clarify what requirements the customer has, what scope you need, and how much of the necessary compliance infrastructure is already in place.
Which companies is SOC 2 relevant for?
SOC 2 is particularly relevant for SaaS, cloud, and technology companies that process sensitive customer data and work with larger or international organizations. There is no general legal requirement to conduct a SOC 2 audit in Germany. However, in enterprise sales processes, a current SOC 2 report can effectively become a prerequisite.
Typical situations include:
- Customers require SOC 2 as part of their vendor risk assessment.
- A company wants to expand more aggressively into the US market.
- Enterprise customers expect independent verification of security controls.
- Existing security questionnaires and individual proof requests are becoming increasingly time-consuming.
Whether SOC 2 makes sense for you depends less on your company's headquarters and more on your customers, markets, and contractual requirements.
Is there an official SOC 2 certification?
No. Strictly speaking, a company is not "SOC 2 certified." SOC 2 is an auditing standard. The result is a SOC 2 report containing the audit opinion of an independent auditor. In the market, however, people often use the simplified term "SOC 2 certification." The audit is conducted by a suitably qualified and licensed CPA firm. The resulting report contains detailed information about the audited system, the relevant controls, and the audit findings. For this reason, a SOC 2 report is usually not made public, but is instead shared in a controlled manner, for example, during a customer procurement process.
What are the requirements of the 5 Trust Services Criteria (TSC)?
The content basis for a SOC 2 audit is formed by the Trust Services Criteria (TSC). The framework is modular. Security is a mandatory component of every SOC 2 audit. The other criteria are included in the scope depending on the business model, the services offered, and customer requirements.
Practical tip for defining the scope: For many companies, the initial focus is primarily on Security. Additional Trust Services Criteria should be included if they are relevant to your product, contractual commitments, or specific customer requirements.
Whether Privacy should be part of the SOC 2 scope also depends on these requirements. For European companies, the GDPR remains relevant regardless – SOC 2 does not replace legal data protection obligations.
What is the difference between SOC 2 Type I and Type II?
The main difference between Type I and Type II lies in the audit period and what is verified regarding the controls:
A Type I report assesses the relevant controls at a specific point in time. With Type II, it is additionally verified whether the controls were actually applied effectively over a defined period. In practice, this period often spans several months. This is why customers who want to understand not just the design of the controls, but also their actual application, often request a Type II report.
SOC 1 vs. SOC 2 vs. SOC 3: Which report is the right one?
The various SOC reports serve different purposes:
- SOC 1: Relates to a service provider's controls that may be relevant to its customers' financial reporting.
- SOC 2: Evaluates controls based on the Trust Services Criteria and is particularly relevant for technology, SaaS, and cloud providers.
- SOC 3: Is a general-use report based on the Trust Services Criteria. It contains significantly less detailed information than a SOC 2 report and can be made publicly available.
For SaaS and technology companies whose customers require detailed proof of internal security controls, SOC 2 is generally the relevant report.
What are the steps involved in a SOC 2 audit?
The path to a SOC 2 report can be simplified into five phases:
- Readiness Assessment: You evaluate which SOC 2 requirements are already met and where gaps still exist.
- Gap Remediation: Missing controls, processes, and documentation are established or adjusted.
- Scope and audit period: Together with the auditor, you determine which systems and Trust Services Criteria will be audited.
- Implementation and evidence collection: For Type II, the relevant controls must be demonstrably applied throughout the audit period.
- Audit and report: The independent CPA auditor reviews the evidence and subsequently issues the SOC 2 report.
For Type II, it is not enough for controls to simply be documented. You must also be able to prove that they actually functioned during the defined period.
What are the realistic costs and timelines for SOC 2?
The costs of a SOC 2 audit cannot be stated as a flat rate. They depend on factors including:
- Company size and complexity
- Scope of the audited system
- Selected Trust Services Criteria
- Type I or Type II
- Existing maturity level of security controls
- Auditor
- necessary external support
- compliance software in use
The duration also varies accordingly. Companies that already have established security processes and documented controls start from a different position than those that still need to build these structures from scratch. For a Type II audit, the defined audit period is an additional factor.
SOC 2 vs. ISO 27001: What are the differences?
European SaaS companies often face the question of whether ISO 27001 or SOC 2 better suits their requirements. The two standards take different approaches:
The decisive factor is therefore not just the question "SOC 2 or ISO 27001?", but rather what evidence your customers and markets expect.
Do I have to build a completely new compliance system for SOC 2?
Not necessarily. Companies that already work with ISO 27001, GDPR, or other compliance frameworks often have existing processes and documentation that can also be relevant for SOC 2.
These include, for example:
- Risk assessments
- Access management
- Incident management
- Vendor management
- Security Policies
- Change Management
- Asset Management
- Documented responsibilities
- Technical and organizational security measures
This does not mean that ISO 27001 or GDPR automatically establish SOC 2 compliance. The requirements and audit methodologies differ. However, many underlying controls can be relevant for multiple frameworks. Instead of treating SOC 2 as a completely new compliance project, it is worth mapping existing controls against SOC 2 requirements first. This reveals what is already in place, which evidence can be reused, and where new controls are actually necessary. This also aligns with a fundamental principle of modern compliance infrastructure: A control should not have to be rebuilt for every framework.
Does SOC 2 replace GDPR compliance in Europe?
No. SOC 2 and GDPR serve different functions. SOC 2 evaluates a company's defined controls based on the Trust Services Criteria. The GDPR, by contrast, is European data protection law and regulates, among other things:
- Legal bases for processing personal data
- Information obligations
- Data subject rights
- Data processing agreements
- Erasure and storage limitation
- Data protection impact assessments
- Notification requirements for data breaches
Even though some technical and organizational measures may overlap, a SOC 2 report does not replace GDPR compliance. For European SaaS companies, both requirements can be relevant in parallel: GDPR due to legal obligations and SOC 2 due to customer or market demands.
FAQ
What is a Bridge Letter (Gap Letter)?
What is a Bridge Letter (Gap Letter)?
A Bridge Letter can be used to bridge the period between the end of an existing SOC 2 reporting period and a later point in time. It typically includes information from the company on whether it is aware of any material changes that could affect the controls described in the SOC 2 report.
A Bridge Letter does not replace a new SOC 2 report.
Who can perform a SOC 2 audit?
Who can perform a SOC 2 audit?
A SOC 2 examination report is issued by an independent CPA firm in accordance with the applicable AICPA auditing standards.
What is the difference between the Carve-out Method and the Inclusive Method for subservice organizations?
What is the difference between the Carve-out Method and the Inclusive Method for subservice organizations?
If a company uses cloud or infrastructure providers, for example, the SOC 2 report must define how these so-called subservice organizations are addressed.
Under the Carve-out Method, the controls of the subservice organization are not directly included in the service organization's examination.
Under the Inclusive Method, relevant controls of the subservice organization are included in the system description and are part of the examination.
Which method is appropriate depends on the scope and the structure of the services provided.







