+91 98804 42758

SOC 2 Audit: What Actually Happens

How the auditor tests your controls, what the five sections of the report contain, and the independence rule that decides who is allowed to sign it.

Updated August 2026 11 min read Information Security

Type 1 vs Type 2

A SOC 2 audit is an examination performed by an independent CPA firm under AICPA attestation standards. The auditor tests whether your controls meet the Trust Services Criteria in scope, then issues a report containing their opinion, your description of the system, and the result of every test they ran.

 Type 1Type 2
Question answeredAre the controls suitably designed?Did they actually operate, over time?
PeriodA single date3–12 month observation window
EvidenceConfiguration and policy as at that dateSamples drawn across the whole window
Fieldwork1–3 weeks2–6 weeks
What buyers ask forAccepted as an interimThe one procurement actually wants

Companies under deal pressure often issue a Type 1 first and follow with a Type 2 covering the subsequent window. That is a legitimate sequence, not a shortcut, provided you tell the customer which one they are receiving.

The Five Criteria and How They Are Tested

Security is mandatory in every report and is delivered through the nine Common Criteria. The other four are included only if scoped in.

CriterionMandatoryHow the auditor tests it
Security (CC1–CC9)YesInspection, inquiry, observation and re-performance across access, change and operations
AvailabilityNoBackup and restore records, capacity monitoring, incident history
Processing IntegrityNoInput validation, error handling, output reconciliation samples
ConfidentialityNoClassification, retention and disposal records
PrivacyNoNotice, consent records, data subject request handling

Every criterion added is more controls and a longer audit. Scope what a customer contract requires — see the full control list on our SOC 2 compliance checklist.

What Happens During Fieldwork

Sampling. For a Type 2 the auditor does not review every change or every access review — they draw samples across the window. A quarterly control gives four opportunities to fail; a daily control gives hundreds. This is why consistency matters more than perfection.

Walkthroughs and inquiry. The auditor interviews control owners and watches the control performed. Answers that do not match the documentation are where most findings originate, which is why rehearsing your team is worth doing.

Re-performance. For some controls the auditor repeats the activity themselves — pulling an access list and checking it against the approved roster, for instance.

How exceptions become qualifications. When a sample fails, the auditor logs an exception. A small number of isolated exceptions with a documented cause usually stay in Section IV as noted deviations. A pattern, or a failure in a control the opinion depends on, becomes a qualified opinion. The report still issues; it names what went wrong.

What Is Inside a SOC 2 Report

Five sections. Most people who receive one read Section I and skip to Section IV, and knowing that changes how you prepare.

SectionContentsWho reads it
IIndependent service auditor's report — the opinion itselfEveryone
IIManagement's assertion — your statement about the systemRarely
IIIDescription of the system — scope, boundaries, subservice organizationsSecurity reviewers checking scope matches what they buy
IVCriteria, controls, tests performed and results, including every exceptionThe customer's security team, line by line
VOther information, not covered by the opinionOptional, often skipped

Section III is where scope disputes happen. If the description covers a system your customer is not buying, the report does not answer their question no matter how clean the opinion is. Getting the system description right at the start is cheaper than re-scoping after a procurement team objects.

Readiness vs the Audit: Who Is Allowed to Do Which

This is the rule most buyers do not know, and the one that decides who you can hire.

ActivityWho does itCan the same firm do both?
Readiness, remediation, evidenceConsultancy (Avantcert)No
The audit and the reportIndependent licensed CPA firmNo

Independence is a requirement of the attestation standard, not a preference. A firm that builds your controls cannot then form an independent opinion on them. If a provider offers to take you "all the way through certification" including the report, ask which licensed CPA firm signs the opinion and what their relationship to the preparer is.

Avantcert does the readiness half: scoping, control implementation, evidence collection across the window, and standing with you through fieldwork. The CPA firm does the other half, and you pay them directly.

Timeline, Start to Report

StageDurationOwner
Readiness & gap assessment2–4 weeksAvantcert
Remediation1–3 monthsYour engineering team, with us
Observation window (Type 2)3–12 monthsYour controls, running
Fieldwork2–6 weeksCPA firm
Report issued2–4 weeksCPA firm

Book the auditor before the window closes, not after. Firms are busiest at calendar year end, and a slipped booking adds a month to a schedule that is already customer-facing.

What a SOC 2 Audit Costs

Two separate invoices from two separate organizations. Avantcert readiness ranges, already discounted 30–50% below typical market rates:

TierEmployeesAvantcert readinessCPA audit feeMax duration
Startup5–50from $7,000Separate90 days
Mid-Market51–200around $16,000Separate90 days
Large Enterprise201–500up to $25,000Separate90 days

If your customers are asking about financial controls rather than security, you may need SOC 1 instead or as well — those engagements run $7,000 to $35,000. Full detail in the SOC 2 certification cost breakdown.

Talk to Us About Your Audit

Tell us which criteria are in scope and when your window needs to close. Scoped estimate within 24 hours.

SOC 2 Audit FAQs

What is a SOC 2 audit?

A SOC 2 audit is an examination performed by an independent CPA firm under AICPA attestation standards. The auditor tests whether your controls meet the Trust Services Criteria in scope and issues a report containing their opinion, your description of the system, and the results of every test performed.

What is in a SOC 2 report?

A SOC 2 report has five sections: Section I, the independent service auditor's report containing the opinion; Section II, management's assertion; Section III, the description of the system; Section IV, the trust services criteria with each control, the test performed and the result; and Section V, optional other information not covered by the opinion. Section IV is where the detail lives and is what a customer's security team will read.

Who performs a SOC 2 audit?

Only a licensed CPA firm can issue a SOC 2 report. Consultants, compliance platforms and MSPs cannot, no matter how the service is described. The firm that prepared you also cannot audit you, because independence is a requirement of the attestation standard.

What is a qualified SOC 2 opinion?

A qualified opinion means the auditor found one or more controls that did not operate effectively during the period. The report still issues, and it still has value, but it names the exceptions. Customers generally accept a qualified report with a clear remediation plan; what they react badly to is discovering the exception themselves.

How long does a SOC 2 audit take?

Fieldwork typically runs two to six weeks and the report is issued two to four weeks after that. For a Type 2 those figures sit on top of the observation window, usually three to twelve months, so a first Type 2 realistically takes six to twelve months end to end.

How much does a SOC 2 audit cost?

The CPA firm's audit fee is separate from readiness and is paid directly to them. Avantcert readiness engagements run from $7,000 for a 5–50 employee company, around $16,000 at 51–200, and up to $25,000 at 201–500 or complex scope.

What is the difference between SOC 1 and SOC 2?

SOC 1 covers controls relevant to a customer's financial reporting and is usually requested by their auditors. SOC 2 covers security and the other Trust Services Criteria and is usually requested by their security team. Payroll, billing and financial processing companies often need both.

Related Reading

Start with the SOC 2 compliance checklist if you are still scoping, SOC 2 certification services for how our engagement runs, the Type 2 walkthrough for more detail on the window, or ISO 27001 vs SOC 2 if you are still choosing.

Official reference: AICPA, SOC 2.

Walk into fieldwork ready

We run readiness, collect the evidence, and stay with you through the auditor's testing. See the full SOC 2 compliance guide for requirements, scope and cost in one place. Section III is where scope disputes actually happen — see what belongs in the system description.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.