A Customer Says We Need SOC 2. What Do We Actually Need to Do?
When a customer says your organization needs SOC 2, the first step is not to immediately hire an auditor.
Start by understanding what the customer actually requires, what type of SOC 2 report they expect, what services and systems should be in scope, what security controls already exist and what gaps need to be addressed before an independent examination.
Hotman Group helps organizations move from customer-driven SOC 2 pressure to a practical readiness, remediation and implementation plan that supports both the immediate business need and the broader cybersecurity program.
The objective is not simply to produce a SOC 2 report. It is to build and operate the controls necessary to provide credible assurance to customers.
What Does It Mean When a Customer Says We Need SOC 2?
Usually, the customer is asking for independent assurance about the security controls supporting the services your organization provides.
But "we need SOC 2" can mean different things.
The customer may be asking for:
- A SOC 2 Type 1 report.
- A SOC 2 Type 2 report.
- A current report covering a particular service.
- Specific Trust Services Criteria.
- Evidence that a SOC 2 program is underway.
- Independent assurance before contract execution.
Clarify the requirement before building the project around an assumption.
What Is SOC 2?
SOC 2 is an independent assurance examination performed by a licensed CPA firm under AICPA standards.
The examination evaluates controls relevant to one or more Trust Services Criteria.
These may include:
- Security.
- Availability.
- Processing integrity.
- Confidentiality.
- Privacy.
The Security criterion is included in every SOC 2 examination. The others are included when relevant to the organization and the services being assessed.
What Is the Difference Between SOC 2 Type 1 and Type 2?
A SOC 2 Type 1 report evaluates whether controls are suitably designed as of a specified date.
A SOC 2 Type 2 report evaluates both the design and operating effectiveness of controls over a defined period.
Customers often prefer Type 2 because it provides evidence that the controls operated over time rather than only existing at one point in time.
Which SOC 2 Type Do Customers Usually Want?
Many customers ultimately want a SOC 2 Type 2 report.
But the answer should come from the customer's actual requirement rather than assumption.
An organization early in its SOC 2 journey may sometimes pursue Type 1 first and then move into a Type 2 period, while others may proceed directly toward Type 2 depending on readiness, timing and business need.
Should We Ask the Customer Exactly What They Require?
Yes.
Useful questions include:
- Do you require Type 1 or Type 2?
- Do you require specific Trust Services Criteria?
- What deadline applies?
- Will evidence of progress satisfy the immediate requirement?
- Does the report need to cover a specific product or service?
- Are there contractual requirements beyond SOC 2 itself?
These answers can materially affect scope, schedule and effort.
What Should We Do Before Engaging a SOC 2 Auditor?
Understand whether the organization is actually ready.
Evaluate:
- Scope.
- Existing controls.
- Policies.
- Risk management.
- Access management.
- Change management.
- Incident response.
- Vendor management.
- Logging and monitoring.
- Evidence.
- Control ownership.
If significant gaps exist, address them before the audit period whenever practical.
Do We Need a SOC 2 Readiness Assessment?
Often, yes.
A readiness assessment helps determine whether the organization has appropriately designed controls and whether those controls can be demonstrated during an independent examination.
A useful readiness assessment should identify:
- What controls already exist.
- What controls are missing.
- Where controls are partially implemented.
- What evidence exists.
- Where ownership is unclear.
- What remediation is required.
- What needs to operate over time before Type 2 testing.
The readiness work should lead directly into implementation and remediation.
What Is the Difference Between SOC 2 Readiness and the SOC 2 Audit?
Readiness work is designed to help the organization prepare.
The SOC 2 examination is the independent assurance engagement performed by a CPA firm.
A consultant may help design controls, remediate gaps, prepare evidence and build the program.
The independent auditor evaluates the resulting environment.
These roles should remain distinct.
Can the Same Firm Prepare Us and Perform the SOC 2 Audit?
The organization should preserve the independence required for the assurance engagement.
The team helping design and implement controls serves a different role from the CPA firm providing independent assurance over those controls.
Separating those functions also creates a healthier readiness process because the implementation work can focus on building a program that actually works rather than merely preparing for one assessor's preferences.
How Do We Define SOC 2 Scope?
Scope should reflect the systems, services, people and processes relevant to the services being described in the report.
Questions may include:
- What product or service is being assessed?
- What systems support that service?
- What infrastructure is involved?
- What people operate the relevant controls?
- What vendors or subservice organizations support the service?
- What data is processed?
- Which Trust Services Criteria are applicable?
Scoping too broadly can create unnecessary work. Scoping too narrowly can produce a report that does not satisfy the customer's assurance need.
Do We Need All Five Trust Services Criteria?
No.
Security is included in every SOC 2 examination.
Availability, Processing Integrity, Confidentiality and Privacy are included when relevant to the services and assurance needs.
The organization should not automatically add criteria simply because more appears stronger.
Each additional criterion creates additional control and evidence considerations.
What Controls Do We Need for SOC 2?
There is not one universal SOC 2 control list that applies identically to every company.
Controls should be designed to address the applicable Trust Services Criteria within the organization's actual environment.
Common areas may include:
- Governance.
- Risk assessment.
- Access control.
- Change management.
- Incident response.
- Vulnerability management.
- Security awareness.
- Vendor management.
- Logging and monitoring.
- Business continuity.
- Data protection.
The control set should describe what the organization actually does.
Do We Need to Buy a SOC 2 Compliance Platform?
No.
Compliance technology can help organize controls, evidence, policies, tasks and audit preparation, but it is not a SOC 2 requirement.
Some organizations benefit significantly from a platform. Others can manage the program effectively using existing systems and disciplined processes.
See whether the organization actually needs a GRC platform.
Will Buying a Compliance Platform Make Us SOC 2 Ready?
No.
A platform may provide templates, integrations and workflows, but the organization still needs to implement and operate the controls.
For example, a platform can request an access review.
It cannot make the access review meaningful if nobody knows who owns it or what should be reviewed.
See how to automate compliance without automating bad processes.
Can We Use Existing Security Controls for SOC 2?
Yes.
If the organization already operates controls through ISO 27001, NIST, CMMC, internal security standards or other programs, many may be reusable.
The organization should map existing controls to the applicable Trust Services Criteria and identify where gaps remain.
See how to reduce duplicate cybersecurity and compliance work.
Do We Need New Policies for SOC 2?
Only where existing documentation does not adequately describe the organization's actual control environment.
Organizations often already have useful policies covering:
- Access control.
- Information security.
- Incident response.
- Change management.
- Vendor management.
- Business continuity.
- Risk management.
Do not create duplicate SOC 2 policies simply because a readiness checklist uses different terminology.
What Evidence Will the SOC 2 Auditor Need?
The auditor will need evidence sufficient to evaluate the controls in scope.
Examples may include:
- Access reviews.
- User provisioning records.
- Change tickets.
- Security training records.
- Risk assessments.
- Vendor assessments.
- Vulnerability scans.
- Incident records.
- Policy approvals.
- System configurations.
- Monitoring records.
The exact evidence depends on the controls and examination period.
See how to centralize cybersecurity and compliance evidence without creating more work.
How Long Does SOC 2 Readiness Take?
There is no universal timeline.
The amount of work depends on:
- Current cybersecurity maturity.
- Scope.
- Control gaps.
- Documentation.
- Evidence practices.
- Resource availability.
- Technology.
- The desired report type.
An organization with mature security controls may be much closer than one beginning with informal processes and limited documentation.
How Long Does a SOC 2 Type 2 Audit Take?
A Type 2 report evaluates controls over a defined examination period.
The organization therefore needs controls operating consistently throughout that period.
Readiness and remediation need to occur early enough that important controls are functioning before or during the required period.
The audit timeline also depends on the CPA firm's testing and report process.
Can We Get SOC 2 in a Few Weeks?
An organization may be able to prepare quickly if the control environment is already mature, but there is no legitimate shortcut around control design, operation and evidence.
A Type 2 examination specifically depends on controls operating over time.
Be cautious about treating SOC 2 as a document that can simply be purchased on an accelerated timeline.
What If the Customer Deadline Is Too Soon?
Determine what the customer actually needs by the deadline.
Possible options may include:
- A documented SOC 2 roadmap.
- A readiness assessment.
- Evidence that remediation is underway.
- A Type 1 report before Type 2.
- Other existing independent assurance.
- A negotiated contractual timeline.
The right answer depends on the customer and commercial situation.
Do not represent that a report exists or that controls operate if they do not.
What If Sales Already Told the Customer We Are SOC 2 Compliant?
Clarify what was represented.
SOC 2 is not a certification in the same sense as ISO 27001, and organizations should be precise about whether they have completed a SOC 2 examination and what report actually exists.
If the organization has not completed the examination, determine what can truthfully be communicated about current readiness and the planned timeline.
Is There Such a Thing as Being "SOC 2 Certified"?
SOC 2 results in an independent attestation report rather than a certification.
Organizations often use informal shorthand in the market, but communications should accurately describe the assurance the organization actually has.
What If We Get Findings During SOC 2 Readiness?
Turn them into remediation work.
Determine:
- What control or process is deficient.
- What risk exists.
- Who owns the correction.
- What needs to change.
- What evidence will demonstrate the fix.
- Whether the control needs time to operate before testing.
See who can help remediate cybersecurity findings.
What If We Have a SOC 2 Report With Exceptions?
Understand what the exceptions actually mean.
Not every exception has the same significance.
Evaluate:
- Which control was affected.
- How significant the issue is.
- Whether it is isolated or systemic.
- What remediation occurred.
- Whether customers need context.
The report should be understood rather than reduced to "pass" or "fail."
Does Passing SOC 2 Mean We Are Secure?
No.
A SOC 2 report provides valuable assurance about defined controls and scope.
It does not mean the organization has no cyber risk or that every security issue is covered by the examination.
See whether passing a cybersecurity audit means the organization is secure and the work is done.
What Happens After We Complete SOC 2?
The controls need to keep operating.
Evidence should continue to be maintained.
Changes need to be evaluated.
Findings need to be remediated.
Risk needs to be managed.
Future examination periods need to be supported.
See how to maintain cybersecurity compliance after certification.
How Do We Avoid a SOC 2 Fire Drill Every Year?
Integrate the controls and evidence into normal operations.
Do not stop performing recurring activities when the auditor leaves.
See how to prepare for cybersecurity audits without constant fire drills.
Can SOC 2 Help With Customer Security Questionnaires?
Yes.
A current SOC 2 report can provide reusable assurance to customers and may reduce the amount of additional diligence required.
But some customers will still ask questions outside the report's scope.
See why customer security questionnaires become so painful and how to fix the underlying problem.
What If We Need ISO 27001 Later?
Much of the underlying security program may be reusable.
SOC 2 and ISO 27001 are different assurance models, but controls, evidence, risk management, governance and security processes can often provide a substantial foundation.
See how much work ISO 27001 may require after SOC 2.
What If We Also Need CMMC or Another Framework?
Do not automatically create a separate cybersecurity program for each requirement.
Map the requirements to the security controls the organization actually operates.
See how to build one cybersecurity program across multiple frameworks.
Should We Build a Common Control Framework?
Possibly, especially if the organization expects to maintain SOC 2 alongside several other requirements.
A common control structure can help reduce duplicate control ownership, evidence and remediation.
See what a common control framework is and whether the organization needs one.
Who Should Own SOC 2 Inside the Organization?
Cyber GRC may coordinate the program, but the underlying controls should be owned by the functions that actually operate them.
For example:
- IT may own access and change controls.
- Security may own monitoring and incident response.
- HR may own personnel-related controls.
- Procurement may participate in vendor-management controls.
- Leadership may own risk and governance decisions.
See how to create clear ownership for cybersecurity controls.
Can We Outsource SOC 2 Readiness and Ongoing Support?
Yes.
Organizations may use external support for:
- Readiness assessment.
- Control design.
- Policy development.
- Remediation.
- Evidence management.
- Audit coordination.
- GRC technology.
- Ongoing Cyber GRC operations.
Internal control owners and leadership still need appropriate accountability for the controls and risk decisions.
How Does Hotman Group Help Organizations With SOC 2?
Hotman Group helps organizations understand what SOC 2 actually requires for their environment and move from customer pressure to an operating control program.
HG can support scope definition, readiness assessments, control design, gap remediation, policy and procedure development, evidence strategy, control ownership, GRC technology, audit preparation and ongoing Cyber GRC operations.
Where independent assurance is required, the SOC 2 examination is performed by the appropriate independent CPA firm while Hotman Group supports the organization on the readiness and implementation side.
The objective is not to create a temporary SOC 2 project that disappears after the report.
The objective is to build cybersecurity controls that support customer trust, business growth and future assurance requirements.
Where Should We Start if a Customer Just Told Us We Need SOC 2?
Start by clarifying exactly what the customer requires and by when.
Then define the likely scope, assess the controls that already exist and identify the real gaps before committing to an audit timeline.
If the customer requirement is part of a broader pattern of new cybersecurity demands, see what to do when a customer introduces a new cybersecurity requirement.
About Hotman Group
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems. Hotman Group designs, builds, implements, remediates, operates and matures cybersecurity and GRC programs.
Learn more about Hotman Group's approach to solving complex cybersecurity and Cyber GRC problems.

