# What is SOC 2? A complete guide to compliance

URL: https://wolfia.com/blog/what-is-soc-2-compliance-guide
Description: What SOC 2 compliance is, how SOC 1, SOC 2, and SOC 3 differ, the audit process, costs, timeline, and requirements. The complete guide for B2B SaaS companies.
Last updated: 2026-09-03

Enterprise security teams don't want to take your word for it anymore. They want proof that your controls work, documented by an independent auditor who watched them operate for months. [SOC 2 certification](https://wolfia.com/) gives them that proof, which is why it's become a hard requirement for selling into healthcare, financial services, and most enterprise SaaS buyers. This guide covers what the framework actually tests, how the audit process works, and what it costs to get compliant without stalling your sales pipeline.

**TL;DR:**

- SOC 2 Type 2 proves your controls work over time; Type 1 only shows design at one point.
- Expect $20K-$80K first-year cost including audit fees, tooling, and internal time.
- US buyers require SOC 2; European buyers prefer ISO 27001; many companies need both.
- The audit takes 6-20 months depending on your auditor and existing security controls.
- Wolfia (used by Amplitude, Miro, and ThoughtSpot) auto-fills post-audit customer questionnaires, RFPs, and DDQs so your team reviews instead of writes.

## What does SOC 2 stand for?

SOC 2 stands for System and Organization Controls 2. It's a framework developed by the AICPA (American Institute of Certified Public Accountants) to audit how service organizations manage and protect customer data.

The "2" matters here. SOC 1 covers financial reporting controls, which is why your payroll processor cares about it. SOC 2 is built for tech and cloud service providers, where the question isn't "can we trust your bookkeeping?" but "can we trust you with our data?" If you are unsure which report your business actually needs, our SOC 1 versus SOC 2 breakdown maps each report to the buyers who ask for it.

SOC 2 audits whether a company's security practices hold up against five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only required criterion. The rest depend on what's relevant to your business. SOC 2 is one of several standards buyers may ask about, and our overview of [the compliance frameworks businesses adopt](/blog/what-are-compliance-frameworks-guide) shows where it fits alongside ISO 27001, HIPAA, and others.

The framework is US-centric but recognized globally, which is why enterprise buyers in virtually every industry now ask for it by default.

## Why SOC 2 compliance matters in 2026

Enterprise buyers don't want to work with vendors on good faith alone. They require proof. SOC 2 has become the de facto entry ticket for selling to mid-market and enterprise companies, particularly in SaaS and cloud services. Skip it, and you're not losing deals on price or features. You're losing them before the conversation even starts.

The data backs this up. [Only 7% of companies](https://www.indusface.com/blog/key-compliance-statistics/) with less than $1M in funding are SOC 2 compliant, compared to [45% of companies](https://www.venn.com/learn/soc2-compliance/soc2-compliance/) generating over $100M in revenue. That gap is deliberate. As companies grow and start targeting larger accounts, SOC 2 becomes a hard prerequisite.

A SOC 2 report signals to procurement teams and security reviewers that your controls have been independently verified. That's the difference between a 90-day security review and a deal that closes in weeks. If you have never sat through an audit before, our overview of [what a compliance audit involves](/blog/what-is-compliance-audit-guide) covers the process and how to prepare.

## The five trust service criteria explained

Each criterion maps to a specific type of risk your customers care about. Here's what each one covers in practice:

### Security

The only mandatory criterion. It covers access controls, firewalls, intrusion detection, and encryption. Every SOC 2 audit starts here.

### Availability

Your systems are accessible as promised. Think uptime SLAs, disaster recovery plans, and incident response procedures.

### Processing integrity

Data is processed completely, accurately, and on time. Relevant for companies handling financial transactions or data pipelines.

### Confidentiality

Sensitive data is protected throughout its lifecycle. This includes encryption at rest and in transit, plus strict access policies.

### Privacy

Covers how personal information is collected, used, retained, and disclosed. Closely tied to compliance frameworks like GDPR and CCPA.

Most B2B SaaS companies start with Security only. If your product touches uptime-sensitive workflows or personal data, Availability and Privacy are worth considering. But expanding scope adds audit time and cost, so start lean unless a customer explicitly requires it.

## SOC 2 Type 1 vs SOC 2 Type 2

Type 1 and Type 2 reports answer different questions. Type 1 asks: are your controls designed correctly at this point in time? Type 2 asks: did those controls actually work over an extended period, typically 3 to 12 months?

Type 1 is faster and cheaper to obtain. It's a reasonable starting point, but enterprise buyers increasingly see it as a placeholder. Security reviewers know that Type 1 only proves policy design was written down on audit day, not that anyone followed those controls.

Type 2 is the standard that matters for serious vendor relationships. Most procurement teams at mid-market and enterprise companies will accept nothing less.

|                       | SOC 2 Type 1                             | SOC 2 Type 2                              |
| --------------------- | ---------------------------------------- | ----------------------------------------- |
| What it tests         | Control design at a single point in time | Control effectiveness over 3 to 12 months |
| Audit duration        | Weeks                                    | Months                                    |
| Cost                  | Lower                                    | Higher                                    |
| Enterprise acceptance | Limited                                  | Widely accepted                           |
| Best for              | Early-stage, initial compliance          | Selling to enterprise buyers              |

Start with Type 1 if you need something on paper quickly. But plan for Type 2 before you're deep in a procurement cycle with a Fortune 500 buyer who asks for it.

## The Five Main Sections of a SOC 2 Report

SOC 2 reports share four required sections, plus an optional fifth for other information, regardless of auditor.

### Independent Auditor Opinion

The verdict. Your auditor confirms whether your controls are designed and operating as described. An unqualified opinion means you passed. A qualified opinion calls out deficiencies. Buyers flip here first to spot red flags. Companies like [Handshake cut questionnaire effort by 90%](https://wolfia.com/case-studies/handshake) by automating responses after achieving SOC 2.

### Management Assertion

Your executive team takes ownership of the controls and confirms they meet SOC 2 criteria. This pins accountability on leadership, not just your security staff. The assertion covers what systems are included, what criteria were selected, and the time period tested. Buyers check this section to see who stands behind the claims and whether the scope matches the services they're evaluating. If the assertion only covers your core platform but they're buying an add-on product, that gap gets flagged during procurement.

### System Description

Defines what's in scope: infrastructure, software, people, processes, and data flows. If your mobile app wasn't audited, it appears here. Buyers compare this to the services they're buying to verify coverage, procurement teams specifically check this section against the SOW before approving a vendor. [Vendor security assessment platforms](https://wolfia.com/blog/vendor-security-assessment-platforms-enterprise-sales) help speed up this review process.

### Controls and Test Results

The longest section. For Type 2, this lists each control, testing procedures, and results over the audit period. Your report answers many common security questionnaire questions. Buyers scan for exceptions or failures. Clean results accelerate vendor approval. Exceptions trigger follow-up calls. Auditors typically document each exception with the control tested, the sample, and the instance that failed. A single missed quarterly access review shows up as one line item, not a failed audit. Auditors distinguish isolated exceptions from systemic control failures, and only the latter typically triggers a qualified opinion.

Wolfia maps your SOC 2 control IDs directly to questionnaire responses. When a buyer asks about your encryption standards or access review cadence, Wolfia pulls the answer from your tested controls and cites the specific section of your report. Your team reviews instead of rewriting the same answers across dozens of spreadsheets.

### Other Information

Optional details like subservice organizations or user entity controls. If you use AWS, Azure, or GCP for hosting, you reference their SOC 2 reports here instead of re-auditing their infrastructure. Buyers trace these dependencies to map shared responsibility boundaries. They want to know which controls belong to you and which belong to your cloud provider. User entity controls are the ones your customers need to implement on their end, like enforcing MFA for their users or restricting API key access. If these aren't clearly documented, buyers will ask about them during security review.

## Who needs SOC 2 compliance?

SOC 2 is voluntary. No law mandates it. But that distinction matters less every year, because enterprise procurement teams have made it a de facto requirement.

If you're a B2B SaaS company, cloud provider, or tech vendor with enterprise customers, you need SOC 2. The industries where it's effectively non-negotiable include healthcare, financial services, and any sector handling sensitive personal or financial data. Sell into those verticals without it, and [security reviews](https://wolfia.com/blog/third-party-risk-management-guide) stall before they begin.

SOC 2 is less urgent if you sell exclusively to small businesses or consumers who don't run formal vendor assessments. But the moment you target mid-market or enterprise accounts, expect the question on every deal.

## How much does SOC 2 cost?

SOC 2 costs more than the audit invoice alone. The audit fee is just one line item in a longer bill.

For small to midsize companies, [SOC 2 Type 2 audit fees](https://www.brightdefense.com/resources/soc-2-audit-costs/) typically run $12,000 to $20,000. Larger organizations pay $30,000 to $100,000 or more depending on scope and auditor.

Factor in the full picture and first-year costs usually land between $20,000 and $80,000:

- Readiness assessment: $5,000 to $15,000
- Compliance tooling: $5,000 to $20,000 annually
- Remediation work: varies widely
- Internal engineering and GRC time: often the biggest hidden cost

That last one surprises most teams. Getting to audit-ready means someone has to write policies, close control gaps, and manage the auditor relationship. If that falls on a security engineer or a one-person GRC team, you're looking at weeks of diverted focus.

## SOC 2 audit timeline and process

The full SOC 2 Type 2 process runs [6 to 20 months](https://soc2auditors.org/insights/soc-2-timeline/), depending on who you hire. Specialist auditors typically finish in 6 to 10 months. Big Four firms run 12 to 20 months.

The process breaks into three phases:

- Readiness: Gap assessment, policy writing, and control implementation get you to a baseline before the clock starts.
- Observation period: The auditor watches your controls operate in practice over 3 to 12 months.
- Audit completion: Evidence review, testing, and report issuance wrap everything up.

Companies with security controls already in place move through readiness faster. Starting from scratch means budgeting extra months before the observation window even opens.

## SOC 1 Explained: Financial Reporting Controls

SOC 1 reports target service organizations that handle processes affecting their clients' financial statements. If your service touches how clients record, process, or report financial data, you need one.

The audit covers controls related to financial reporting accuracy. Auditors test whether your systems and processes protect the integrity of financial data flowing through your services.

Who needs SOC 1? Payroll processors, accounting service providers, claims processing firms, and benefits administrators. Any organization where your service becomes part of a client's financial reporting chain.

Banks reviewing your clients' financials want proof that vendors in the accounting stack maintain proper controls. SOC 1 provides that proof.

## The Core Differences: SOC 1 vs SOC 2

The choice between SOC 1 and SOC 2 comes down to what your service does for clients. SOC 1 proves your controls protect financial data accuracy. SOC 2 proves your controls protect information security and privacy.

| Feature                 | SOC 1                                  | SOC 2                                        |
| ----------------------- | -------------------------------------- | -------------------------------------------- |
| Focus                   | Financial reporting controls           | Security, availability, privacy controls     |
| Audience                | Client auditors and finance teams      | InfoSec, procurement, risk management        |
| Common Industries       | Payroll, accounting, claims processing | SaaS, cloud services, data processors        |
| Trust Services Criteria | Not applicable                         | Security (required) plus 4 optional criteria |

Most SaaS companies need SOC 2. If your service doesn't touch client financial statements, SOC 1 isn't relevant. But if you process payroll or handle accounting functions, you need SOC 1 regardless of whether you also need SOC 2.

Some companies need both reports. A payroll service with cloud infrastructure requires SOC 1 for financial controls and SOC 2 for data security.

## SOC 1 Type 1 vs Type 2: Timeline and Testing Differences

SOC 1 Type 1 checks your financial reporting controls on a single day. The auditor reviews documentation, interviews your team, and confirms controls exist as described. No historical testing occurs.

SOC 1 Type 2 requires three to 12 months of evidence. Auditors sample transactions, review access logs, and verify controls operated consistently throughout the period, beyond a single audit day snapshot.

Starting with Type 1 makes sense when you've just implemented new controls or need quick proof for a specific client. Client auditors prefer Type 2 because it shows ongoing compliance over time, beyond good intentions on paper.

## SOC 3: The Public-Facing Alternative

SOC 3 reports are the public version of SOC 2. Same independent audit, same controls tested, but stripped of technical details and designed for public distribution.

You can post SOC 3 reports on your website. Share them with prospects before they sign an NDA. Include them in marketing materials. The report confirms an auditor validated your security controls without revealing how those controls work.

What's missing? The detailed control descriptions, test procedures, auditor observations, and findings that make SOC 2 reports hundreds of pages long. SOC 3 gives you a seal of approval, not a technical blueprint. To understand exactly what those longer reports contain, the five main sections of a SOC 2 report are covered above.

SOC 3 works well on a Wolfia Trust Center where prospects can validate your security posture and request your full SOC 2 report when they’re ready for due diligence. If you are weighing where to host these documents, our roundup of the [best trust center software for security teams](/blog/best-trust-center-software-saas-security-teams) compares the options.

## When You Need Both SOC 1 and SOC 2

Some companies serve clients who demand both reports. Payroll providers with cloud infrastructure face this. So do benefits administrators offering SaaS portals. HR tech companies processing financial data need both.

Your client base determines what you need. Financial services clients expect SOC 1. Tech buyers require SOC 2. Serve both industries, and you'll field requests for both reports during sales cycles.

Running both audits at once saves time and money. Many controls overlap between SOC 1 and SOC 2. Access management, change control, and monitoring apply to both frameworks. Your auditor tests these controls once and includes results in both reports.

## SOC 2 vs ISO 27001

SOC 2 and ISO 27001 serve similar goals but work differently in practice. SOC 2 is an attestation report issued by a CPA firm, shared under NDA with specific customers who request it. ISO 27001 is a public certification issued by an accredited body, valid for three years with annual surveillance audits.

The choice often comes down to where your customers are. US enterprise buyers ask for SOC 2. European and global buyers lean toward ISO 27001. Many companies end up pursuing both as they expand internationally.

|             | SOC 2               | ISO 27001                  |
| ----------- | ------------------- | -------------------------- |
| Origin      | US (AICPA)          | International (ISO/IEC)    |
| Output      | Attestation report  | Public certification       |
| Sharing     | Under NDA           | Publicly shareable         |
| Audit cycle | Annual              | 3-year with surveillance   |
| Best for    | US enterprise sales | Global or European markets |

If you're US-focused and selling to enterprise SaaS buyers, start with SOC 2. Add ISO 27001 when European deals require it. If you're weighing that second certification, our [ISO 27001 certification guide](/blog/iso-27001-certification-guide) walks through the controls, audit cycle, and timeline in detail.

## SOC Reports vs International Standards: ISAE 3402

ISAE 3402 is the international version of SOC 1. Same purpose, same focus on financial reporting controls. The difference? Geography and governing body.

SOC 1 follows AICPA standards for US markets. ISAE 3402 follows International Auditing and Assurance Standards Board guidelines for global clients. Both cover how service organizations control processes that affect client financial statements.

Most auditors offer combined SOC 1/ISAE 3402 reports. One audit satisfies both US and international client requirements. Your European customers get ISAE 3402 compliance. Your American customers get SOC 1. Same testing period, same controls tested, dual certification.

If you only serve US clients, stick with SOC 1. Operating globally? Request the combined report.

## Common SOC 2 controls and requirements

There's no universal checklist for SOC 2. The AICPA provides points of focus for each criterion, but auditors have discretion. That said, most audits cover the same core controls.

Auditors will check:

- Multi-factor authentication on all critical systems
- Encryption at rest and in transit
- Quarterly access reviews and least-privilege policies
- Change management procedures with documented approvals
- System logging and monitoring with alerting
- Incident response plans with documented test history
- Business continuity and disaster recovery procedures
- Vendor risk management for third-party software

Security is the baseline. If you've added Availability or Privacy to your scope, auditors will also check uptime monitoring, backup systems, and data handling practices against those criteria.

## Preparing for your SOC 2 audit

Getting audit-ready is a process, not a checklist you hand to your auditor on day one. Companies that run into expensive findings almost always skipped the gap assessment phase before their observation period started. For a deeper checklist of controls, evidence, and timelines, our SOC 2 compliance requirements guide breaks down each phase.

Here's the order that works:

- Run a gap assessment against the Trust Service Criteria you're scoping. Identify what controls exist, what's missing, and what's partially in place.
- Close the gaps before the observation period starts. Auditors charge to watch your controls run, not to fix them.
- Write your policies. Incident response, access control, change management, and [vendor risk management](https://wolfia.com/blog/security-questionnaires-complete-guide) all need documented procedures.
- Set up evidence collection. [Automate evidence collection where possible](https://wolfia.com/blog/security-questionnaire-automation-complete-guide). Manual evidence gathering is where audits stall.
- Run an internal readiness check before the auditor arrives. Treat it like a mock audit.

Skipping steps moves the problem later in the process, where fixes are costlier and delays hit active sales cycles.

## Building Your SOC 2 Compliance Checklist

SOC 2 doesn't hand you a checklist. You build controls around your specific system and customer commitments.

Start with access management. Document who can access what, how you grant permissions, and when you review them.

Change management tracks how code and infrastructure updates move through approval, testing, and deployment without breaking security controls.

System operations covers monitoring, backups, disaster recovery, and incident response. Prove you detect problems and fix them following documented procedures.

Vendor management matters when third parties touch customer data. Track contracts, security reviews, and access termination for every vendor in your stack. Building this out properly is its own discipline, and our [third-party risk management guide](/blog/third-party-risk-management-guide) covers the assessment methods auditors expect to see. Auditors will ask which subprocessors have access to customer data, what security assessments you ran on them, and how you handle offboarding when a vendor relationship ends. Maintain an inventory of all vendors with data access, their SOC 2 or equivalent certifications, and the date of your last review.

Document everything. Auditors need evidence your controls run consistently, and prospects will ask about them in security questionnaires for years after the audit. Keep policies, procedures, and evidence organized so you can produce them on demand. Teams using Wolfia build this documentation into a knowledge base that feeds both audit evidence and questionnaire responses, so the same documentation serves both purposes.

## Maintaining SOC 2 Compliance After Certification

SOC 2 reports expire after 12 months. Annual renewal audits keep your report current for customer needs.

Renewal audits run smoother than initial certification. Auditors review the same controls but focus on what changed: new systems, updated policies, staff turnover, or infrastructure changes. Evidence collection becomes routine once you track access reviews, vulnerability scans, training completion, and backup tests as they happen.

[97% of organizations](https://www.a-lign.com/resources/the-state-of-compliance-2026) conduct at least two audits per year, with 74% of enterprise companies conducting four or more. Multiple frameworks like ISO 27001, HIPAA, or PCI DSS often overlap, creating audit fatigue.

Run internal tests quarterly to maintain control effectiveness. Catch drift early before auditors flag issues in formal reviews. Document changes to systems or processes immediately so you're not rebuilding context months later during evidence requests. Setting up [continuous SOC 2 compliance monitoring](/blog/what-is-compliance-monitoring-guide) keeps your controls in check year-round instead of scrambling right before each renewal audit.

## Common SOC 2 Challenges and How to Overcome Them

Documentation gaps create the biggest delays. Teams find missing policies and undocumented procedures weeks into their audit. Start a documentation sprint three months early. Assign owners to each policy with weekly progress checks.

Resource constraints hurt when compliance falls on one person who's also handling security questionnaires. Distribute evidence collection across departments. Engineering tracks change logs. HR provides background checks. IT runs access reviews. For the questionnaire side, Wolfia takes that off your plate by auto-filling responses from your existing documentation so your compliance lead isn't buried in spreadsheets during audit season.

Evidence collection needs structure from day one. Create folders by control category and set monthly reminders for access logs, vulnerability scans, and training records. Pulling six months of logs during testing wastes time.

Post-certification control maintenance demands automation. Manual access reviews get skipped when workload spikes. Automate user provisioning, log collection, and policy acknowledgments to stay audit-ready year-round.

## How Security Questionnaires Relate to SOC 2 Reports

Achieving SOC 2 can meaningfully cut security questionnaire volume, based on what customers report. Buyers attach it to procurement workflows as a pre-qualification filter. If you have a clean Type 2 report, reviewers can skip many of the detailed questions they'd otherwise ask about access controls and encryption.

The report answers entire sections of vendor assessments before you open the spreadsheet. Questions about penetration testing frequency, background check policies, and disaster recovery procedures? Already documented in your SOC 2. Buyers reference specific control IDs instead of making you write custom responses.

This speeds up deal cycles because security review moves from a blocker to a checkbox. Instead of weeks of back-and-forth on questionnaires, the buyer's security team reads your report, confirms coverage, and moves you forward. The remaining questions that fall outside your SOC 2 scope are where tools like Wolfia pick up, pulling from your policies and past responses to fill in the gaps.

## How Wolfia accelerates post-SOC 2 sales cycles

Getting SOC 2 certified is step one. What follows is a constant stream of [security questionnaires from buyers](https://wolfia.com/blog/best-security-questionnaire-automation-tools-b2b-saas) who want to verify your controls beyond the report itself. That's where teams get buried.

[Wolfia auto-fills security questionnaires](https://wolfia.com/blog/best-security-questionnaire-automation-tools-b2b-saas) across Excel, PDF, Word, and vendor portals by pulling directly from your SOC 2 documentation, policies, and knowledge base. Instead of a 2 to 4 week turnaround per questionnaire, your team reviews answers instead of writing them from scratch.

Your SOC 2 report proves you have controls. Wolfia turns that proof into closed deals faster.

## Final thoughts

[SOC 2 certification](https://wolfia.com/) solves your credibility problem with enterprise buyers. The next problem is speed. Your sales team can't wait 2-4 weeks per security review when deals are on the line. We built Wolfia because every company hits this wall after certification. [Book 15 minutes](https://wolfia.com/demo?ref=blog) to see how auto-filled questionnaires cut your review cycle from weeks to hours without adding headcount.

## FAQ

### How long does a SOC 2 Type 2 audit actually take?

Plan for 6 to 20 months depending on your auditor and starting point. Companies with existing security controls typically finish in 6 to 10 months with specialist auditors, while Big Four firms often run 12 to 20 months.

### What's the real cost of getting SOC 2 certified?

First-year costs typically range from $20,000 to $80,000 when you include the audit fee ($12,000 to $20,000 for most companies), readiness assessment, compliance tooling, and internal time. The biggest hidden cost is the engineering and GRC hours required to write policies, close control gaps, and manage the auditor relationship.

### Do I need SOC 2 Type 1 or should I go straight to Type 2?

Type 2 is what enterprise buyers actually accept. Type 1 proves your controls were designed correctly on audit day, while Type 2 proves they worked over 3 to 12 months. Start with Type 1 only if you need something on paper immediately, but plan for Type 2 before you're deep in a procurement cycle with a major buyer.

### Is SOC 2 actually required by law?

No. SOC 2 is voluntary, but enterprise procurement teams have made it a requirement in practice. If you're a B2B SaaS company selling to mid-market or enterprise accounts, especially in healthcare or financial services, you'll lose deals before conversations start without it.

### What happens after I get my SOC 2 report?

You'll face a constant stream of security questionnaires from buyers who want to verify your controls beyond the report itself. Each questionnaire takes 2 to 4 weeks to complete manually, which is where most teams get buried post-certification.

### What's the main difference between SOC 1 and SOC 2?

SOC 1 proves your controls protect financial data accuracy for clients whose financial statements depend on your service. SOC 2 proves your controls protect information security and privacy across five Trust Services Criteria. Most SaaS companies need SOC 2, while payroll processors and accounting service providers need SOC 1.

### Do I need both SOC 1 and SOC 2 if I'm a payroll provider?

If your service processes payroll calculations that affect client financial statements and you also store employee data in a cloud system, yes. Financial services clients expect SOC 1 for the accounting controls, while tech buyers require SOC 2 for data security. Running both audits at once saves time since many controls overlap.

### When should I use SOC 3 instead of SOC 2?

Use SOC 3 as a public-facing seal of approval on your website or Trust Center where prospects want quick validation before signing an NDA. You'll still need the full SOC 2 report for serious buyers during due diligence, since SOC 3 strips out the technical control descriptions and test procedures that InfoSec teams review.

### Can I use my SOC 2 report to skip security questionnaires?

Your SOC 2 report can meaningfully cut security questionnaire volume and answer many questions about controls, but buyers still send hundreds of custom questionnaires asking product-specific questions, AI governance details, and data retention policies your report doesn't cover.

### Should I get ISO 27001 or SOC 2 first?

Get SOC 2 first if you're selling to U.S. enterprise buyers. It's faster, cheaper, and what procurement teams request during vendor reviews. Add ISO 27001 later when expanding to European markets or when customers explicitly require it.

### What happens if my SOC 2 audit finds control failures?

Your auditor documents exceptions in the Controls and Test Results section, which buyers read carefully. Minor issues with clear remediation plans rarely kill deals, but multiple failures in critical controls like access management or encryption will stall vendor approval and trigger follow-up security calls.

### Do I need all five Trust Services Criteria for SOC 2?

Security is mandatory for all SOC 2 audits. The other four (Availability, Processing Integrity, Confidentiality, and Privacy) are optional based on your customer contracts and commitments. Most companies audit Security plus one or two others depending on what they promise in SLAs and agreements.
