Understanding SOC 2: A Quick Reference

If you're here, someone has probably asked you for a SOC 2 report, or you know you'll need one soon. Here's what you actually need to understand to use Auditley effectively.

What SOC 2 actually is

SOC 2 is an audit performed by an independent CPA firm. They examine your company's controls and issue a report stating whether those controls are designed and operating effectively. You don't get certified in the way you might with ISO; you receive a report that your customers and prospects can review.

Criteria vs controls: the most important distinction

SOC 2 is built around criteria: specific requirements published by the AICPA that your company must demonstrate. Auditley's control library is organised around these criteria. Examples include the entity maintains a commitment to integrity and ethical values, or the entity restricts physical access to facilities. A control is the specific thing your company actually does to satisfy a criterion. There is no fixed number of controls per criterion. A small team might satisfy a criterion with one clear piece of evidence. A larger company might have several controls supporting the same criterion, and a single control can sometimes support more than one criterion at once. This means Auditley isn't telling you exactly what to build. It's telling you what each criterion requires and what good evidence typically looks like, so you can build the right controls for your specific company.

A note on the word control

You'll see the word control used throughout Auditley to describe each requirement you're tracking on your dashboard. Technically, what you're looking at are SOC 2 criteria: the formal requirements set by AICPA. We use control because it's the term most people use day to day and it's what you'll hear from your auditor and your team. It's worth knowing the difference though, especially once you start building your own internal controls and evidence to satisfy each criterion. In practice the two words are often used interchangeably across the industry, including by Auditley.

Trust Service Categories

SOC 2 criteria are grouped into five categories. Security is mandatory for every SOC 2 report. Availability, Confidentiality, Processing Integrity, and Privacy are optional and only included if relevant to your business and customer commitments. Most first-time SOC 2 companies start with Security only. You can manage which categories apply to you in Settings.

Type I vs Type II

A Type I report assesses whether your controls are designed appropriately at a single point in time. A Type II report assesses whether your controls actually operated effectively over a period, typically 6 to 12 months. Most enterprise customers will eventually want to see a Type II report, but many companies start with a Type I to get a report out faster, then move to Type II.

Evidence

Evidence is the proof that a control actually happened: a screenshot, an exported log, a signed document, a ticket showing something was done. Auditors don't take your word for it; they test the evidence. This is why Auditley's evidence locker exists: to keep proof organised and attached to the right criterion as you go, rather than scrambling to find it the week before your audit.

What Auditley does and doesn't do

Auditley guides you through every criterion with plain-English explanations of what's required and what auditors typically look for, helps you draft policies tailored to your setup, and keeps your evidence organised and exportable. Auditley does not perform your audit. That's done by a licensed CPA firm you engage separately. Think of Auditley as the preparation layer that gets you organised and confident before that audit begins.

Where to start

If you're not sure where to begin, start with the Security category controls in the order they appear on your dashboard. Work through one at a time: read the guidance, ask the AI assistant if anything is unclear, gather your evidence, and mark it ready when you're confident it would hold up to an auditor's questions.