Skip to main content

Explainers

There is no such thing as "SOC 2 certified"

SOC 2 is an attestation report with an opinion, a period and an auditor. Nobody issues a certificate. What the phrase hides, why it spreads, and the four facts to ask for instead.

Solomon AmosPublished 15 Sep 2026Updated 18 Sep 20269 min read

Hands signing a document with a fountain pen
Photo by Scott Graham on Unsplash

Search any vendor’s security page and there is a decent chance it says the company is "SOC 2 certified". It is one of the most common phrases in B2B marketing and it describes something that does not exist. Understanding why is the fastest way to become a better reader of vendor evidence, because the correct vocabulary tells you exactly what to ask for. This explainer covers what SOC 2 produces, why the wrong word spreads, what it hides, and how the index records the framework without it.

0
Certificates issued by a SOC 2 engagement
The output is an attestation report
66%
of B2B buyers check for SOC 2 before signing
Agency, SOC 2 statistics roundup
45
Vendors with public SOC 2 facts in the CertReports index
18 September 2026

What SOC 2 actually is

SOC 2 is an attestation engagement performed by a licensed CPA firm under the AICPA attestation standards. The service organisation writes a description of its system and asserts that its controls meet the Trust Services Criteria. The auditor examines that description and those controls and issues an opinion. The output is a report addressed to the service organisation, with restricted distribution.

Despite it commonly being referred to as a "SOC 2 certification," SOC 2 is an attestation. SOC 2 auditors do not certify that a given company has met the standard; instead, the report attests to what they’ve observed in the organization’s security program.

Nothing in that process issues a certificate, sets a pass mark, or creates a public register. A vendor can have an unqualified opinion, a qualified one, or an adverse one. Two vendors with "SOC 2" on their pages can differ by report type, period, criteria in scope, carve-outs and exceptions, and the badge shows none of it.

Why the wrong word spreads

Three reasons. Buyers ask "are you SOC 2 certified?" because the phrase is familiar from ISO, where a certificate genuinely exists, and vendors answer in the same words. Compliance platforms sell badges, and a badge looks like a certificate. And "we hold a SOC 2 Type II report for the twelve months to 31 March 2026, issued by a named firm" is longer than "SOC 2 certified" and fits worse on a landing page. None of these is dishonest. All of them lose information a reviewer needs.

People reviewing documents together
The report is addressed to the vendor and shared under NDA. The public facts are the type, period, criteria and firm. · Photo by Annie Spratt on Unsplash

What the phrase hides

The badge saysThe report might say
SOC 2 certifiedType I, design only, one date, eighteen months ago
SOC 2 certifiedType II, Security only, six-month period, two exceptions on access reviews
SOC 2 certifiedType II, all five criteria, twelve months, cloud provider carved out
SOC 2 certifiedA readiness assessment by a consultancy, not a CPA firm
SOC 2 certifiedA report for a different legal entity or product than the one on your order form

Every row is a real pattern from captured vendor pages.

The comparison with ISO 27001

ISO 27001 is a certification: an accredited certification body audits an information security management system against the standard and issues a certificate with a scope, sites and a three-year validity subject to annual surveillance. SOC 2 is an attestation: a CPA firm examines controls against criteria and issues an opinion for a period. The words are not interchangeable, and the difference decides what evidence exists. ISO produces a document you can check for edition, scope and expiry; SOC 2 produces a report you must read for type, period, criteria and exceptions.

ISO 27001SOC 2
OutputCertificateAttestation report
Issued byAccredited certification bodyLicensed CPA firm
ValidityThree years with annual surveillanceA period; ages out about three months after the period end
Public registerNone with bulk access; CB lookupsNone; the report is restricted
Correct phrase"ISO 27001 certified, scope X, edition 2022""SOC 2 Type II report, period ending X, audited by Y"

The four facts to ask for

  1. Report type: Type I (design at a point in time) or Type II (design and operating effectiveness over a period). See Type I versus Type II.
  2. Period end date, and a bridge letter if it is more than three months old.
  3. Trust Services Criteria in scope. Security is mandatory; Availability, Processing Integrity, Confidentiality and Privacy are optional.
  4. The CPA firm. CertReports links firms to their auditor pages so you can see how many reports they sign.
Reports and a pen on a desk
Four facts fit on one line of a trust centre and answer most of what a reviewer would otherwise email sales to ask. · Photo by Helloquence on Unsplash

How CertReports records it

The index never uses the phrase as a state. A SOC 2 row records the report type, period end, auditor and criteria, each with a capture date and a snapshot. When a page only shows a badge, the row is vendor-stated; when the auditor confirms the engagement, it becomes verified by auditor. There is no registry to verify against, which is why SOC 2 has fewer verified rows than any registry-backed framework. See the SOC 2 hub for every vendor with public evidence, and the reading guide for what to do with the report once you have it.

If you write vendor copy

Say "SOC 2 Type II report, period ending March 2026, audited by [firm]". It is shorter than an argument with a reviewer and it is what the reviewer will ask for anyway.

People also ask

Is there a SOC 2 certificate?

No. A SOC 2 engagement produces an attestation report with an auditor’s opinion. Some platforms issue badges, but no body certifies SOC 2 and there is no register of certified companies.

What does SOC 2 compliant mean?

Usually that the vendor holds a SOC 2 report with an unqualified opinion. The phrase does not say which type, which period, which criteria or which firm, all of which change what the report proves.

Who can issue a SOC 2 report?

Only a licensed CPA firm, under the AICPA attestation standards. A readiness assessment or gap report from a consultancy is not a SOC 2 report.

Is SOC 2 mandatory?

No law requires it. It is demanded by buyers: Agency’s roundup puts it in 70 to 85 percent of enterprise B2B RFPs, which is why it feels compulsory for vendors selling to enterprises.

How long is a SOC 2 report good for?

A Type II covers its period and is generally accepted for up to twelve months after the period end, with a bridge letter covering the first few months of the gap.

What is the difference between SOC 2 and ISO 27001?

ISO 27001 is a certification of a management system by an accredited body, valid for three years with surveillance. SOC 2 is an attestation report on controls for a period by a CPA firm. Different outputs, different evidence.

SOC 2attestationvocabularyAICPAvendor review
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like