Skip to content
Capability/Compliance Frameworks

SOC 2

Trust services criteria for service organizations

01 / Overview

SOC 2 reports demonstrate the effectiveness of controls related to security, availability, processing integrity, confidentiality, and privacy. Thalorin streamlines SOC 2 compliance with automated evidence collection, auditor collaboration features, and continuous monitoring that maintains audit readiness year-round.

SOC 2 is an attestation, not a certification, and the distinction determines almost everything about how it should be run. A CPA firm expresses an opinion on whether controls the organisation itself defined were suitably designed and, in a Type II, operated effectively across an observation window. There is no fixed control list to implement — which is why two SOC 2 reports can describe wildly different security postures and both be clean.

The organisation picks which of the five Trust Services Criteria are in scope. Security, the common criteria, is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are elective, and each one added expands both the control population and the evidence burden. Scoping too broadly at the outset is the most common self-inflicted cost.

For a Type II, the observation window is the real constraint. Evidence must demonstrate operation throughout the period, typically three to twelve months, which means the control has to be running before the window opens. A control implemented in month five of a six-month window produces an exception, not a pass.

Thalorin treats the observation window as a first-class object: controls carry the period they must evidence, sampling is drawn from real operational records, and a control that stops producing evidence raises a gap while the window is still open rather than at fieldwork.

02 / Challenges

Framework compliance requires sustained effort

Scope is a choice with a price

Adding Trust Services Criteria beyond Security multiplies the control population and the evidence collection burden. Organisations often add Privacy or Processing Integrity for perceived market value without costing the ongoing work.

Evidence must span the whole window

Type II tests operation across a period. A control that was not running at the start of the window cannot be evidenced retroactively, and the resulting exception appears in a report customers will read.

Auditor judgement varies

Because the organisation defines its own controls, different firms reach different conclusions about sufficiency. Control language that satisfied one auditor may draw a finding from another.

Continuous drift between reports

A report is a point in time about a past window. Between reports, infrastructure changes, people leave, and controls quietly stop operating — usually discovered during the next fieldwork.

03 / Capabilities

How Thalorin helps

SOC 2AICPA TSC

Trust services criteria mapping

Map the Trust Services Criteria in scope to the specific controls that address them, so scope decisions carry a visible cost and a control shared with ISO 27001 is tested once.

Evidence collection automation

Bind evidence to the observation window, flagging any control whose evidence does not span the full period before fieldwork begins.

Auditor collaboration portal

Give the auditor scoped access to the evidence and sample populations directly, so fieldwork is not a chain of email attachments assembled by hand.

Control effectiveness testing

Draw sample populations from real operational records rather than assembling them by hand at audit time.

Exception tracking

Track exceptions and management responses as living items rather than as report artifacts discovered at the end.

Type II continuous readiness

Maintain vendor and subservice organisation coverage, including the carve-out or inclusive method decision, so the next Type II period starts ready rather than being reconstructed.

Questions

SOC 2: common questions

What is the difference between SOC 2 Type I and Type II?

Type I opines on whether controls are suitably designed at a single point in time. Type II opines on whether they operated effectively across an observation window, typically three to twelve months. Type I is faster and is often used as a first step, but most enterprise buyers ask for Type II because design without operation proves little.

How long does a SOC 2 take?

The binding constraint is the observation window, not the audit. For a Type II with a six-month window, controls must be operating before the window opens, so realistic end-to-end timelines run from readiness work through the window to fieldwork and report issuance. Compressing the window shortens the calendar but weakens the report in the eyes of sophisticated buyers.

Which Trust Services Criteria should I include?

Security is mandatory. Add others only where a customer contract or a genuine commitment requires it: Availability if you make uptime commitments, Confidentiality if you hold customer data under confidentiality obligations, Processing Integrity for transaction accuracy, Privacy if you handle personal information under a privacy notice. Each addition is an ongoing cost, not a one-time one.

Is SOC 2 a certification?

No. It is an attestation report issued by a CPA firm expressing an opinion. There is no certificate and no certifying body, which is why the correct phrasing is that an organisation has completed a SOC 2 examination or holds a SOC 2 report, not that it is SOC 2 certified.

Can SOC 2 evidence be reused for ISO 27001?

Substantially, yes. The underlying controls overlap heavily — access management, change management, incident response, vendor management — even though the frameworks structure and assess them differently. The efficiency comes from holding one control state and projecting it into both, rather than running two independent evidence collection exercises.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about SOC 2.

See how one evidence artifact satisfies SOC 2 requirements alongside every other framework you carry.