"SOC 2 compliant" is on every B2B SaaS homepage. Most of those vendors can't tell you which Trust Services Criteria the audit covered, what the audit window was, or whether the report is Type I or Type II. Here's the buyer-side explainer.
What SOC 2 actually is
SOC 2 is an audit framework published by the American Institute of CPAs (AICPA). It's not a certification — there's no government-issued seal. It's an attestation by an independent CPA firm that the vendor's controls are designed and operating effectively.
The auditor tests the vendor's controls against one or more of the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Most enterprise buyers want Security, Availability, and Confidentiality at minimum.
Type I vs Type II
A Type I report attests that the vendor's controls are designed correctly as of a single point in time. It's a snapshot. A Type II report attests that the controls operated effectively over a period — typically 3 to 12 months — and includes the auditor's actual test results.
Type II is what enterprise buyers should ask for. Type I is a starting point but doesn't tell you the controls actually work in production.
What the auditor actually tests
For each Trust Services Criterion, the auditor pulls real evidence over the audit window:
- Security: access reviews, change tickets, incident logs, vulnerability scans, employee offboarding records, vendor risk assessments.
- Availability: uptime telemetry, incident response records, capacity plans, disaster recovery test results.
- Confidentiality: encryption configs (at rest and in transit), key management procedures, data classification, DLP controls.
The auditor also confirms that the controls were actually running in production — not just documented. That's the difference between Type I and Type II.
How to read the report
The SOC 2 report is usually 30-80 pages. The most important sections for buyers:
- Section 1: the auditor's opinion — pass or qualified opinion.
- Section 2: the vendor's system description — what's in scope and what's not.
- Section 3: the controls list and the auditor's test results — including any exceptions.
- Section 4: management's response to any exceptions.
A clean Type II report with zero exceptions is the gold standard. A report with documented exceptions is normal for a young company — what matters is how the vendor responded to them.
What to ask before you trust the seal
Three questions that cut through the marketing:
- Which Trust Services Criteria does the audit cover? (Security only, or Security + Availability + Confidentiality?)
- What's the audit window? (3 months is barely useful; 6-12 months is meaningful.)
- How many exceptions did the report include, and what were they? (Some exceptions are minor — a missed quarterly review that was caught the next month. Others indicate control failures.)
Beyond SOC 2
SOC 2 is the table stakes for enterprise sales. It's not the ceiling. Mature vendors also pursue ISO 27001 (international security management), HIPAA (US healthcare data), PCI DSS (payment card data), and FedRAMP (US federal workloads). Each covers territory SOC 2 doesn't.
Where we stand: KaryaFlow has not completed a SOC 2 audit. Our controls are built against the Trust Services Criteria and the audit is planned, but there is no report and we will not imply otherwise. ISO 27001 is scoped and on the roadmap; we make no HIPAA claim. Current status always lives on security and compliance.
Applying this post's own advice to us: do not accept the claim, ask for the report. If a vendor cannot hand you one — including us — that is your answer, and it should shape what you are willing to run on the platform today. Talk to us about what we can evidence now.
