Steps to Implement SOC 2 Type 2 for US SaaS Companies: Never Lose a $2M Deal Again
Alexander Sverdlov
Security Analyst

SOC 2 shows up in almost every enterprise procurement cycle a US SaaS company runs into. A security questionnaire lands, a line asks for your SOC 2 report, and suddenly a deal you thought was closing is waiting on a document you do not have yet. I have guided a lot of SaaS teams through this, and the pattern is always the same: the companies that plan SOC 2 early treat it as routine, and the ones that get caught flat-footed lose weeks of momentum at the worst possible moment.
This is a practical guide to implementing SOC 2 Type 2 for a US SaaS company. It covers what Type 1 and Type 2 actually mean, how the two fit together, the controls you need to stand up, and the sequence that keeps you from burning cash and calendar. No inflated promises about closing deals in a fortnight, just how the work really goes.
Want SOC 2 done without the guesswork?
Atlant Security runs SOC 2 readiness engagements led by a former Microsoft security consultant. We map your gaps, help you stand up real controls, and get you audit-ready. See the SOC 2 service.
Type 1 Versus Type 2: What You Are Actually Buying
SOC 2 is an attestation performed by a licensed CPA firm against the AICPA Trust Services Criteria. There are two report types, and understanding the difference is the foundation of a sane implementation plan.
SOC 2 Type 1 assesses whether your controls are suitably designed and in place at a single point in time. It is a snapshot. An auditor confirms the control exists and is designed to meet the criteria on the report date.
SOC 2 Type 2 assesses whether those controls operated effectively over a period, commonly three to twelve months. It is a film, not a photograph. The auditor samples evidence across the window to confirm the control worked consistently, not just on one day.
Enterprise buyers care about Type 2 because it proves durability. Type 1 has a legitimate role as a first milestone: it demonstrates your program is real and designed correctly while your Type 2 observation window runs. Some procurement teams will accept a Type 1 report with a committed Type 2 date as an interim step. Others will wait for Type 2. You cannot control which camp a given buyer falls into, so the right strategy is to stand up strong controls once and let both reports fall out of the same work.
Dimension | SOC 2 Type 1 | SOC 2 Type 2 |
|---|---|---|
What it proves | Controls are designed and in place on a date | Controls operated effectively over a period |
Evidence basis | Point in time | Sampled across the observation window |
Typical timeline | Weeks once controls exist | Observation window of three to twelve months plus audit |
Buyer confidence | Interim assurance | Strong, durable assurance |
Source: AICPA Trust Services Criteria.
Choosing Your Trust Services Criteria and Scope
SOC 2 covers five Trust Services Criteria, and you do not need all of them. Security, formally the Common Criteria, is mandatory. The other four are optional and you include them only if they match commitments you make to customers.
Security (required): protection against unauthorized access, the baseline every report includes.
Availability: include it if you make uptime or reliability commitments, which most SaaS companies do.
Confidentiality: include it if you handle customer data designated as confidential under contract.
Processing Integrity: include it if data accuracy and completeness of processing is core to what you sell, such as financial or transactional platforms.
Privacy: include it if you collect and process personal information and want to attest to how you handle it.
Adding criteria you do not need inflates cost and evidence burden. Most early-stage SaaS companies start with Security and Availability, and add Confidentiality when a customer contract demands it. Scope your systems just as deliberately: the report covers a defined system boundary, so include the production environment and the supporting infrastructure that touches customer data, and consciously exclude what does not.
The Controls You Need to Stand Up
SOC 2 does not hand you a prescriptive list of controls the way a checklist standard would. It gives you criteria and expects you to implement controls that satisfy them. For a typical US SaaS company, the working set looks like this.
Access and identity
Enforce least privilege across production systems and cloud accounts.
Require multi-factor authentication for all administrative and remote access.
Run a documented joiner, mover, and leaver process so access follows employment changes.
Perform and record periodic access reviews. Auditors will sample these directly.
Change management
Require code review and approval before production deployment.
Keep an audit trail linking changes to tickets and approvals.
Separate the ability to write code from the ability to push it to production where team size allows.
Monitoring and logging
Centralize logs and retain them for a defined period.
Alert on security-relevant events and, critically, keep evidence that alerts were investigated to closure.
Track availability against your stated objectives if Availability is in scope.
Data protection
Encrypt data in transit and at rest using current standards.
Manage encryption keys with restricted access.
Classify data and apply handling rules that match your Confidentiality commitments.
Vulnerability and risk management
Run recurring vulnerability scanning and remediate on a defined timeline. A structured vulnerability assessment program gives you the recurring evidence auditors expect.
Perform an annual risk assessment and keep the output.
Commission a penetration test. It is not strictly mandated by the criteria, but most enterprise buyers and many auditors expect one, and it validates that your controls hold up in practice.
Governance and vendor management
Maintain approved information security policies that people actually follow.
Run security awareness training and record completion.
Perform due diligence on subservice providers and keep the records.
A Sensible Implementation Sequence
Here is the order that keeps SOC 2 from derailing your engineering roadmap.
Readiness assessment first. Before you spend money on an auditor, get an honest gap analysis against the criteria. A dedicated SOC 2 readiness engagement tells you what you already have, what is missing, and what will take the longest, so you can plan the observation window realistically.
Remediate the gaps. Stand up the missing controls and, just as importantly, wire up the evidence generation so each control produces an artefact automatically. A control with no evidence trail is invisible to an auditor.
Consider a Type 1 as a milestone. If you have a buyer who will accept interim assurance, a Type 1 report documents that your controls are designed correctly while the clock runs on Type 2. It is optional, not a shortcut.
Run the observation window. This is the part no one can compress. Your controls must operate for the chosen period, often three months for a first Type 2, while evidence accumulates. Discipline here is what makes the audit painless.
Select an auditor and complete fieldwork. Engage a licensed CPA firm to perform the examination. They will request evidence samples across your window, interview control owners, and issue the report.
Plan the annual renewal. SOC 2 Type 2 is not one and done. Enterprise buyers expect a current report each year, so the controls and evidence collection must keep running continuously.
A note on automation platforms: tools that continuously collect evidence from your cloud and identity providers genuinely reduce the manual load, and I recommend them. They do not implement controls for you, and they do not replace judgment about scope and design. Treat them as evidence plumbing, not as the program itself.
How Much It Costs and How Long It Takes
Costs vary with company size, scope, and how much you outsource, so I will not invent a figure. The honest ranges to plan around are these: the auditor's fee for the examination itself, the cost of a compliance automation platform if you use one, the internal engineering time to build and operate controls, and any advisory support for readiness and remediation. For a first Type 2, plan on a few months of preparation before the observation window even begins, then the window itself, then several weeks of audit fieldwork. Anyone promising a full Type 2 in a couple of weeks is describing a Type 1 or is misrepresenting the process.
Where SOC 2 Programs Go Wrong
Starting the observation window before controls are stable. If controls change mid-window or generate gaps, the auditor documents exceptions and your report looks weaker. Stabilize first.
Collecting evidence manually at the end. Reconstructing three months of access reviews the week before fieldwork is where teams burn out. Automate evidence from day one.
Over-scoping the criteria. Including Processing Integrity or Privacy when no customer requires them adds cost for no commercial return.
Treating it as a one-time project. Let the program lapse and next year's renewal starts from a cold engine.
No clear owner. Without someone accountable, controls drift and evidence gaps appear. This is exactly where a virtual CISO earns its keep, owning the program so your engineers can build product.
Making SOC 2 a Sales Asset
A clean SOC 2 Type 2 report does real commercial work. It shortens security reviews, removes a common procurement blocker, and signals to enterprise buyers that you take their data seriously. The way to capture that value is to have the report ready before the deal needs it, not to scramble when a questionnaire arrives. That is a planning decision you make quarters ahead, and it is why the strongest SaaS teams treat SOC 2 as ongoing infrastructure rather than a fire drill. If your buyers are financial institutions, pairing SOC 2 with a fintech security program tends to clear their diligence faster.
Frequently Asked Questions
Should I do Type 1 first or go straight to Type 2?
It depends on your buyers. If a customer will accept interim assurance, a Type 1 gives you something to show while the Type 2 window runs. If your buyers only value Type 2, skip Type 1 and run the observation window directly. Either way you build the same controls once, so the decision is about timing and buyer expectations, not about doing separate work.
How long is the Type 2 observation period?
It is your choice within reason, commonly three months for a first report and often extending to six or twelve months on renewal. A longer window gives buyers more confidence but delays your first report. Many companies start with three months to get a report in hand, then move to a twelve-month cycle.
Do we need a penetration test for SOC 2?
The Trust Services Criteria do not name a penetration test as a required control, but recurring vulnerability scanning is expected and most enterprise buyers and auditors look for an annual penetration test. Practically, budget for one. It also gives you concrete evidence your controls work rather than just exist.
Which Trust Services Criteria should a SaaS company include?
Security is mandatory. Add Availability if you make uptime commitments, which most SaaS companies do. Add Confidentiality when a customer contract requires it. Only include Processing Integrity or Privacy if they are genuinely core to your product, since each added criterion increases cost and evidence load.
Can a small startup realistically get SOC 2?
Yes, and a smaller environment is often faster to bring into scope because there are fewer systems and people. The main constraints are the observation window, which no one can skip, and having someone own the program. Many small teams use a virtual CISO to fill that ownership gap without a full-time hire.
Does SOC 2 need to be renewed?
Yes. Enterprise buyers expect a current Type 2 report, typically covering the most recent twelve months, so controls and evidence collection run continuously. Treat SOC 2 as an operating program, not a project with an end date.
Get SOC 2 Done Properly
SOC 2 Type 2 is very achievable when you sequence it right: scope deliberately, stand up real controls, automate the evidence, run the observation window with discipline, and keep the program alive year over year. The teams that struggle are the ones that start late and try to manufacture a report under deal pressure. If you want an experienced hand to run your SOC 2 readiness and keep the program on track through the audit and beyond, talk to us.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.