SOC 2
Last updated
Definition
SOC 2 is an attestation report, defined by the AICPA, in which an independent CPA firm examines a service organization's controls against five Trust Services Criteria – security (mandatory), availability, processing integrity, confidentiality, and privacy. A Type I report tests whether controls were designed correctly at a point in time; a Type II tests whether they operated effectively over an observation window, typically 3–12 months. It is not a certification and not a law: the deliverable is a report you share with buyers under NDA.
Why it matters to an MSP
Nobody is required to have SOC 2 – it is demanded. The requests come from enterprise procurement and vendor-risk teams reviewing your clients as suppliers, and increasingly from your own larger prospects and cyber insurance carriers asking the same of you. That creates two lines of work. Helping a client reach it is high-stickiness compliance revenue: you implement and evidence controls you mostly deploy anyway – MFA, EDR, backup, logging, offboarding – and the CPA firm audits them. Getting your own is a sales asset that closes deals a competitor without one cannot bid on. Budget honestly for the latter: a small MSP typically spends $20,000–$50,000 in the first year – a compliance-automation platform and readiness work at $5,000–$20,000, plus an audit fee of $10,000–$30,000 for a Type II from a mid-size firm – and roughly half that annually to renew. Timeline is 6–12 months from kickoff to a Type II report, since the observation window alone is at least three months. Skip straight to Type II if you can wait; sophisticated buyers discount a Type I. See how it compares with other frameworks in compliance frameworks comparison.
Related terms: Compliance, Cyber Insurance, CMMC