Search any vendor’s security page and there is a decent chance it says the company is "SOC 2 certified". It is one of the most common phrases in B2B marketing and it describes something that does not exist. Understanding why is the fastest way to become a better reader of vendor evidence, because the correct vocabulary tells you exactly what to ask for. This explainer covers what SOC 2 produces, why the wrong word spreads, what it hides, and how the index records the framework without it.
- 0
- Certificates issued by a SOC 2 engagement
- The output is an attestation report
- 66%
- of B2B buyers check for SOC 2 before signing
- Agency, SOC 2 statistics roundup
- 45
- Vendors with public SOC 2 facts in the CertReports index
- 18 September 2026
What SOC 2 actually is
SOC 2 is an attestation engagement performed by a licensed CPA firm under the AICPA attestation standards. The service organisation writes a description of its system and asserts that its controls meet the Trust Services Criteria. The auditor examines that description and those controls and issues an opinion. The output is a report addressed to the service organisation, with restricted distribution.
Despite it commonly being referred to as a "SOC 2 certification," SOC 2 is an attestation. SOC 2 auditors do not certify that a given company has met the standard; instead, the report attests to what they’ve observed in the organization’s security program.
Nothing in that process issues a certificate, sets a pass mark, or creates a public register. A vendor can have an unqualified opinion, a qualified one, or an adverse one. Two vendors with "SOC 2" on their pages can differ by report type, period, criteria in scope, carve-outs and exceptions, and the badge shows none of it.
Why the wrong word spreads
Three reasons. Buyers ask "are you SOC 2 certified?" because the phrase is familiar from ISO, where a certificate genuinely exists, and vendors answer in the same words. Compliance platforms sell badges, and a badge looks like a certificate. And "we hold a SOC 2 Type II report for the twelve months to 31 March 2026, issued by a named firm" is longer than "SOC 2 certified" and fits worse on a landing page. None of these is dishonest. All of them lose information a reviewer needs.
What the phrase hides
| The badge says | The report might say |
|---|---|
| SOC 2 certified | Type I, design only, one date, eighteen months ago |
| SOC 2 certified | Type II, Security only, six-month period, two exceptions on access reviews |
| SOC 2 certified | Type II, all five criteria, twelve months, cloud provider carved out |
| SOC 2 certified | A readiness assessment by a consultancy, not a CPA firm |
| SOC 2 certified | A report for a different legal entity or product than the one on your order form |
Every row is a real pattern from captured vendor pages.
The comparison with ISO 27001
ISO 27001 is a certification: an accredited certification body audits an information security management system against the standard and issues a certificate with a scope, sites and a three-year validity subject to annual surveillance. SOC 2 is an attestation: a CPA firm examines controls against criteria and issues an opinion for a period. The words are not interchangeable, and the difference decides what evidence exists. ISO produces a document you can check for edition, scope and expiry; SOC 2 produces a report you must read for type, period, criteria and exceptions.
| ISO 27001 | SOC 2 | |
|---|---|---|
| Output | Certificate | Attestation report |
| Issued by | Accredited certification body | Licensed CPA firm |
| Validity | Three years with annual surveillance | A period; ages out about three months after the period end |
| Public register | None with bulk access; CB lookups | None; the report is restricted |
| Correct phrase | "ISO 27001 certified, scope X, edition 2022" | "SOC 2 Type II report, period ending X, audited by Y" |
The four facts to ask for
- Report type: Type I (design at a point in time) or Type II (design and operating effectiveness over a period). See Type I versus Type II.
- Period end date, and a bridge letter if it is more than three months old.
- Trust Services Criteria in scope. Security is mandatory; Availability, Processing Integrity, Confidentiality and Privacy are optional.
- The CPA firm. CertReports links firms to their auditor pages so you can see how many reports they sign.
How CertReports records it
The index never uses the phrase as a state. A SOC 2 row records the report type, period end, auditor and criteria, each with a capture date and a snapshot. When a page only shows a badge, the row is vendor-stated; when the auditor confirms the engagement, it becomes verified by auditor. There is no registry to verify against, which is why SOC 2 has fewer verified rows than any registry-backed framework. See the SOC 2 hub for every vendor with public evidence, and the reading guide for what to do with the report once you have it.
If you write vendor copy
Say "SOC 2 Type II report, period ending March 2026, audited by [firm]". It is shorter than an argument with a reviewer and it is what the reviewer will ask for anyway.
People also ask
Is there a SOC 2 certificate?
No. A SOC 2 engagement produces an attestation report with an auditor’s opinion. Some platforms issue badges, but no body certifies SOC 2 and there is no register of certified companies.
What does SOC 2 compliant mean?
Usually that the vendor holds a SOC 2 report with an unqualified opinion. The phrase does not say which type, which period, which criteria or which firm, all of which change what the report proves.
Who can issue a SOC 2 report?
Only a licensed CPA firm, under the AICPA attestation standards. A readiness assessment or gap report from a consultancy is not a SOC 2 report.
Is SOC 2 mandatory?
No law requires it. It is demanded by buyers: Agency’s roundup puts it in 70 to 85 percent of enterprise B2B RFPs, which is why it feels compulsory for vendors selling to enterprises.
How long is a SOC 2 report good for?
A Type II covers its period and is generally accepted for up to twelve months after the period end, with a bridge letter covering the first few months of the gap.
What is the difference between SOC 2 and ISO 27001?
ISO 27001 is a certification of a management system by an accredited body, valid for three years with surveillance. SOC 2 is an attestation report on controls for a period by a CPA firm. Different outputs, different evidence.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
SOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read
What is a bridge letter, and how much should a buyer trust one?
Solomon Amos · 12 Sep 2026 · 9 min read