SOC 2 position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What SOC 2 does well

  • US procurement signal — widely recognized; standard procurement question.
  • Trust Services Criteria broad enough to cover most SaaS concerns.
  • Type 2 operational effectiveness rigor — evidence over a period, not point-in-time.
  • Auditor independence required.
  • Auditor mature ecosystem — many CPA firms with SOC 2 capability.
  • Privacy TSC complements GDPR for US-EU work.
  • Combined audit infrastructure with ISO 27001 reduces dual-audit cost.

What SOC 2 does poorly

  • No public certificate. Reports are private; sharing requires NDA.
  • US-centric. Lower recognition in EU procurement vs ISO 27001.
  • CPA firm variance. Auditor depth and rigor vary; some firms produce "compliant" reports with minimal substance.
  • TSC interpretation flexibility can produce inconsistent rigor.
  • Annual cycle — same report-effort each year, no longer-term certificate equivalent.
  • No standard control catalog. Org defines controls mapped to TSC; comparison between orgs' SOC 2 reports requires reading the controls.
  • SOC 3 (public summary) less commonly used than SOC 2; recognition limited.

Evidence

  • Universal among US enterprise SaaS — Type 2 typically by Series B / mid-market revenue.
  • CPA firm consolidation — Schellman, A-LIGN, Coalfire, BSI Americas, Big Four. Substantial market.
  • Combined ISO 27001 + SOC 2 common — Schellman, A-LIGN especially.
  • Privacy TSC adoption growing as US state privacy laws proliferate.

Personal calibration

  • For US-customer-facing AI / SaaS work: SOC 2 Type 2 baseline expectation.
  • For cross-border: ISO 27001 + SOC 2 dual positioning.
  • For solo / small-team: SOC 2 first-time cost (~€15-50k) gates; align practices without formal report initially.

See also