SOC 2 is an attestation framework created by the American Institute of Certified Public Accountants (AICPA) to evaluate how well a service organization safeguards customer data. An independent auditor examines your controls against the Trust Services Criteria and reports on how those controls are designed and, in a Type II examination, how they actually operate over time. As of 2026, AICPA guidance also expects your report to address AI whenever AI is part of your service or your controls.
For SaaS providers, cloud vendors, and any company handling customer data, it has become the standard way to prove security to buyers. Done well, you do the work once and use it many times: one report answers dozens of customer security questionnaires instead of a new one for every deal.
Why companies pursue SOC 2
Trust has become a sales requirement
Faster sales cycles
Unlocks more deals and closes them faster
One report answers the security questionnaire before it slows down an enterprise deal.
Stronger security posture
Tighten real controls, not just paperwork
The work behind the report improves how you actually manage access, monitoring, vendors, and incidents.
Brand credibility
Show the market you take security seriously
Independent, AICPA-recognized evidence valued by security-conscious customers, partners, and investors.
Board and investor confidence
Give leadership independent proof the program works
A third-party opinion on your controls answers the question your board and investors are already asking.
Trust Services Criteria
Five criteria. Security is always in scope
Every SOC 2 report covers Security. The other four are added when they match what you promise customers. We help you choose the scope that buyers expect without taking on criteria you do not need.
Security
Required in every report. Protects systems and data against unauthorized access and disclosure.
Availability
Your system is available for operation and use as committed in your service agreements.
Processing integrity
System processing is complete, valid, accurate, timely, and authorized.
Confidentiality
Information designated as confidential is protected as committed or agreed.
Privacy
Personal information is collected, used, retained, disclosed, and disposed of in line with your commitments.
New for 2026: SOC 2 and AI
Using AI? Your SOC 2 now has to account for it
In September 2026, the AICPA issued new guidance, Q&A Section 9561, on how a service organization’s use of AI affects SOC 1 and SOC 2 examinations. The Trust Services Criteria still apply, but when AI is part of your service or your controls, auditors expect your report to address it.
System description
Disclose how you use AI before your auditor asks We help you describe the types of AI you use, the models and data behind them, and how AI supports your service.
AI risk assessment
Address the AI risks auditors now look for We assess accuracy, hallucinations, bias, explainability, data poisoning, prompt injection, and privacy, and design controls for each.
AI governance
Show clear oversight of every AI system We define AI roles, responsibilities, and accountability, human review of AI output, and policies, and uncover shadow AI use.
AI at your vendors
Cover the AI your vendors use on your behalf We extend vendor risk management to subservice organizations and providers whose AI affects your service.
Report scope
Choose criteria that hold up when customers rely on AI If customers depend on AI output, Processing Integrity may be expected. We help you select a scope your auditor will accept.
Report types
SOC 2 Type I or Type II: which is right for you?
SOC 2 Type I: point in time
A fast first milestone
Confirms your controls are suitably designed as of a specific date. Often the first step toward a Type II observation period.
SOC 2 Type II: over time
The report most enterprise buyers expect
Confirms your controls operate effectively over an observation period, typically three to twelve months.
Included at no extra cost
SOC for Cybersecurity, included with every engagement
Every InfoGuard SOC 2 engagement includes a SOC for Cybersecurity report at no additional scope or fee. One engagement, two AICPA-recognized reports: one built for your customers, one built for your board, regulators, and public stakeholders.
SOC 2
SOC for Cybersecurity
Purpose
Reports on controls for security, availability, processing integrity, confidentiality, or privacy.
Reports on your entire cybersecurity risk management program.
Scope
A specific service organization, business unit, or service line.
Your whole organization's cybersecurity program.
Criteria
AICPA Trust Services Criteria.
Can use a recognized framework such as NIST CSF or ISO 27001.
Third-party risk
Subservice organizations can be carved out.
Must be addressed directly; it cannot be carved out.
Distribution
Restricted to customers and partners who need it.
General use; safe to share publicly.
Our SOC 2 approach
Cybersecurity at our core. Compliance built on it
Compliance should validate good cybersecurity, not substitute for it.
For 15+ years, InfoGuard has approached compliance through the lens of cybersecurity. We understand the technology, architecture, threats, controls, and operational realities behind the requirements, not just the checklist.
Cybersecurity at our core
Our expertise goes beyond policies and documents.
Deep technical expertise
Our cybersecurity extends to AI, cloud, applications, infrastructure, identity and access, networks, data protection, governance, risk, and emerging technologies.
Hands-on senior leadership
Our senior cybersecurity experts work alongside your team to implement practical controls and carry out the engagement through readiness, audit, and your final report.
Controls that hold up
We design controls your team can operate day to day across the full observation period, so Type II testing does not surface exceptions.
Your compliance investment should deliver more than checklists and documentation. It should improve your cybersecurity as well.
How we help
From gap assessment to your final report, and beyond
01
Readiness & Gap Assessment
We evaluate your controls against the Trust Services Criteria that apply to you, identify every gap an examiner will test, and map the system boundary: every application, vendor, and data flow in scope.
02
Scope & Controls Design
We help you select the right criteria, design the technical and administrative controls to satisfy them, and build the policies and procedures your auditor expects to see before testing begins.
03
Build & Remediation
We implement the tooling and operational controls your design calls for, closing gaps in access management, monitoring, encryption, vendor management, and incident response, and assemble the evidence trail.
04
Mock Audit & Readiness
A mock audit that mirrors the real examination confirms your evidence and controls hold up before the clock starts on a Type II observation period.
05
Examination & Report
Our independent audit partner performs the official examination as part of your engagement: one point of contact through your final report.
06
Sustain & Monitor
A SOC 2 report has a shelf life; your controls should not drift in between. Ongoing monitoring, evidence collection, and policy maintenance keep your next period ready.
FAQ
SOC 2 questions, answered
Reports and process
What is the difference between a SOC 2 Type I and Type II report?
A Type I report evaluates whether your controls are suitably designed as of a single point in time. A Type II report evaluates the same controls over an observation period, typically three to twelve months, and confirms they actually operated effectively throughout it. Most enterprise buyers expect a Type II.
What is a SOC 2 readiness assessment, and do I need one?
A readiness assessment is a practice run through the evidence and control testing your auditor will perform, done before the official examination begins. It is the most reliable way to catch a gap while it is still inexpensive to fix.
How long does the SOC 2 process typically take?
A Type I report can often be issued within weeks once your controls are in place. A Type II report requires an observation period of three to twelve months on top of that, so most organizations budget several months from initial gap assessment to a final report.
Does SOC 2 now cover AI?
Yes, when AI is relevant to your service. In September 2026, the AICPA issued Q&A Section 9561, which explains how a service organization’s use of AI affects SOC 2 examinations. The Trust Services Criteria are unchanged, but auditors now expect AI to be addressed in your system description, risk assessment, AI governance, and vendor oversight.
How long is a SOC 2 report valid?
There is no fixed expiration date, but most enterprise buyers expect a report covering a period that ended within the last twelve months, so organizations typically renew on an annual cycle.
What is the most common reason organizations fail their audit?
Incomplete evidence and inconsistently followed policies are the most common failure points, not missing technical controls. A readiness assessment before the real examination is the most reliable way to catch this while it is still cheap to fix.
Cost, scope, and fit
How much does a SOC 2 audit cost?
Cost depends on your organization’s size, the number of Trust Services Criteria in scope, and how much remediation your environment needs. There is no flat fee. We provide a firm quote after an initial gap assessment.
Do I need SOC 2 if I am not a large company?
Possibly, yes. If your product touches customer data and you sell into enterprise or mid-market accounts, a SOC 2 report is frequently a prerequisite to closing the deal, regardless of your company’s size.
Do you work with early-stage startups, not just large enterprises?
Yes. Early-stage and growth-stage companies are often the ones facing their first enterprise security questionnaire with the fewest resources in place to answer it. That is exactly where InfoGuard helps most.
What is the difference between SOC 2 and ISO 27001?
Both evaluate your information security controls, but SOC 2 is an AICPA attestation aimed primarily at U.S. and North American buyers, while ISO 27001 is an internationally recognized certification against a management-system standard. Many organizations pursuing global enterprise deals eventually hold both.
Cybersecurity first
A checkbox compliance provider won't cut it
You need real cybersecurity expertise to earn a report that holds up under an enterprise buyer’s scrutiny.
Tell us what you’re trying to accomplish. We’ll reply with next steps, whether that’s a gap assessment, a mock audit, or a straight introduction to our audit partner.