SOC 2 buyer guide: scope, evidence, and auditor selection
SOC 2 is an AICPA attestation examination of controls relevant to Security and any additional Trust Services Criteria selected in scope.
Plan readiness separately from the examination and choose a licensed CPA firm based on documented evidence, not unsupported badges or rankings.
From requirement to report
| Phase | Buyer task | Output |
|---|
| Requirement | Confirm what customers ask for | Report type, criteria, deadline |
| Readiness | Design controls and collect evidence | Resolved gaps and defined system |
| Examination | Support testing and respond to exceptions | Auditor evidence and management responses |
| Delivery | Review description and distribution terms | Final restricted-use SOC 2 report |