SECURITY ASSURANCE EXPLAINED

What is SOC 2, and when does your business actually need one?

SOC 2 is an independent audit report that proves a service organisation manages customer data securely against five trust criteria: security, availability, processing integrity, confidentiality and privacy. If a prospect, investor or enterprise buyer has asked you for “your SOC 2”, this page explains exactly what they want, why, and how to get there without panic.

Book a conversation

What SOC 2 actually is

SOC 2, short for System and Organization Controls 2, is an attestation report produced by an independent certified public accountant against criteria defined by the American Institute of Certified Public Accountants. It is not a certificate you display on a wall. It is a detailed report describing the controls you operate to protect customer data, and the auditor’s professional opinion on whether those controls are designed properly and, in the case of a Type II report, whether they worked over a period of time. The report exists so that one company can give another company evidence-based assurance about how its data will be handled, without that customer having to run their own inspection.

SOC 2 is built around the AICPA’s Trust Services Criteria. Security is mandatory in every report and is often called the common criteria. The other four, availability, processing integrity, confidentiality and privacy, are included only when they are relevant to the service you provide. A payroll platform might add processing integrity and confidentiality; a hosting provider might add availability. You scope the report to what your customers genuinely care about.

Type I versus Type II, and why the difference matters

There are two flavours of SOC 2 report, and buyers treat them very differently. A Type I report assesses whether your controls are suitably designed at a single point in time. It is a snapshot. A Type II report assesses whether those same controls operated effectively across a defined observation window, usually three to twelve months. Type II is the one enterprise procurement teams really want, because it shows discipline sustained over time rather than a tidy desk on audit day. Most organisations start with Type I to establish the baseline, then move to a Type II covering the following period. Planning that sequence early avoids the common trap of promising a Type II you have no evidence history to support.

When a business actually needs SOC 2

You need SOC 2 when you store, process or transmit other organisations’ data and those organisations need assurance before they will trust you. In practice the trigger is almost always commercial. A large customer’s security questionnaire stalls a deal. An enterprise contract makes the report a condition of signing. An investor’s technology due diligence flags the absence of any independent security assurance. SaaS companies, managed service providers, data processors and fintech firms hit this wall earliest because their entire value sits on top of customer data.

SOC 2 is voluntary, not a legal requirement. No UK statute compels it. But the absence of one increasingly behaves like a barrier to growth in mid-market and enterprise sales. If you are weighing the cost against the benefit, the honest framing is that SOC 2 is a sales enabler and a trust signal, not a compliance obligation. That distinction shapes how aggressively you should pursue it and what scope makes sense, which is exactly the kind of decision our cyber security consulting work is built to help leaders make.

How SOC 2 differs from the standards it gets confused with

SOC 2 is frequently muddled with adjacent frameworks, and getting the distinction right saves money and effort. ISO 27001 is the international standard for an information security management system; it certifies that you run a system for managing security, whereas SOC 2 reports on the operating effectiveness of specific controls. Many companies eventually hold both, because international buyers often ask for ISO and North American buyers often ask for SOC 2.

Cyber Essentials, the UK government-backed scheme, is a far lighter baseline focused on five technical controls, and it is a sensible first step long before SOC 2 becomes relevant. PCI DSS is narrower still, governing card payment data specifically. The newer NIS2 regime is regulatory rather than voluntary and applies to essential and important entities. SOC 2 sits apart from all of these as a customer-facing assurance report rather than a certificate or a legal mandate. Choosing the right combination for your customers and regulators is a governance call, and one that belongs on the agenda of any board taking cyber governance seriously.

What achieving SOC 2 involves in practice

Reaching a clean SOC 2 report is a programme, not a purchase. It starts with scoping: deciding which trust criteria apply and which systems are in or out. Then comes a readiness assessment, an honest gap analysis between the controls you operate today and the controls the report will test. You remediate the gaps, which usually touches access management, change control, vendor management, logging, encryption and incident handling. You then run those controls long enough to generate evidence, before the independent auditor performs the examination and issues the report.

The work that decides success happens before the auditor arrives. Most failures trace back to controls that look fine on paper but generate no evidence in practice, or a scope set so wide it becomes unmanageable. A clear owner, realistic timelines and a tested incident response plan matter more than any tool. This is the kind of structured security build-out delivered through a CISO as a service engagement or a virtual CISO, where senior security leadership runs the programme without the cost of a permanent hire.

What SOC 2 does not cover, and where AI changes the picture

SOC 2 tells a customer about the controls in scope on the date of the report. It is not a guarantee against breach, and it does not automatically cover everything your business does. New systems, new data flows and new tools fall outside the report until you bring them in. Generative AI has made this sharper: staff feeding customer data into unsanctioned tools, or shadow AI, can quietly undermine the very controls your SOC 2 attests to. Treating AI governance as part of your control environment, rather than a separate problem, keeps the report honest as your technology estate grows.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

That experience of running security and technology at board level across private-equity-backed and enterprise environments means Starkhorn can scope, lead and de-risk a SOC 2 readiness programme the way a buyer’s procurement team and an investor’s diligence both expect, whether as a fractional CIO and CISO or through a focused vCISO engagement.

Frequently asked questions

Is SOC 2 a certification?

No. SOC 2 is an attestation report written by an independent auditor, not a certificate. The auditor gives a professional opinion on whether your controls are designed properly and, for a Type II report, whether they operated effectively over time. There is no logo to display in the way ISO 27001 or Cyber Essentials provide.

Do UK companies need SOC 2?

There is no UK law requiring SOC 2. UK companies pursue it because customers, particularly large or North American ones, demand it before signing, and because investors expect independent security assurance. It is a commercial and trust requirement rather than a legal one.

What is the difference between SOC 2 and ISO 27001?

ISO 27001 certifies that you operate an information security management system to an international standard. SOC 2 reports in detail on the operating effectiveness of specific controls against the AICPA Trust Services Criteria. ISO is more common with international buyers, SOC 2 with North American ones, and many firms eventually hold both.

Should I start with Type I or Type II?

Most organisations begin with a Type I report to establish that controls are designed correctly at a point in time, then move to a Type II covering the following observation period. Enterprise buyers usually want Type II because it proves controls worked over months, not just on audit day. Plan the sequence early so you build the evidence history a Type II needs.

How does SOC 2 relate to Cyber Essentials?

Cyber Essentials is a far lighter UK baseline covering five technical controls and is a sensible first step. SOC 2 is a much deeper, customer-facing assurance report. Many organisations achieve Cyber Essentials early and only pursue SOC 2 once enterprise customers start demanding it. A Cyber Essentials readiness check is a quick way to see where your foundations stand.

START WITH THE FOUNDATIONS

Not sure your basics would survive an audit?

Before you commit to a SOC 2 programme, it is worth knowing whether your core controls would even pass the lighter UK baseline. Our free Cyber Essentials Readiness check shows you where the gaps are in minutes, and gives you a clear sense of how far you are from a fuller assurance regime. When you want a senior view on scope, sequence and cost, book a conversation.

Cyber Essentials Readiness check Book a conversation