Stefan Coetzeecreated 2026-05-12updated 2026-05-121 min readposition
Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.
What SOC 2 does well
US procurement signal — widely recognized; standard procurement question.
Trust Services Criteria broad enough to cover most SaaS concerns.
Type 2 operational effectiveness rigor — evidence over a period, not point-in-time.
Auditor independence required.
Auditor mature ecosystem — many CPA firms with SOC 2 capability.
Privacy TSC complements GDPR for US-EU work.
Combined audit infrastructure with ISO 27001 reduces dual-audit cost.
What SOC 2 does poorly
No public certificate. Reports are private; sharing requires NDA.
US-centric. Lower recognition in EU procurement vs ISO 27001.
CPA firm variance. Auditor depth and rigor vary; some firms produce "compliant" reports with minimal substance.
TSC interpretation flexibility can produce inconsistent rigor.
Annual cycle — same report-effort each year, no longer-term certificate equivalent.
No standard control catalog. Org defines controls mapped to TSC; comparison between orgs' SOC 2 reports requires reading the controls.
SOC 3 (public summary) less commonly used than SOC 2; recognition limited.
Evidence
Universal among US enterprise SaaS — Type 2 typically by Series B / mid-market revenue.