SOC 2, explained: it's an attestation, not a certification
What the SOC 2 report is, the Trust Services Criteria, the difference between Type I and Type II, the observation period, honest timelines and cost lines. An informational guide, not a pitch.
- There's no “SOC 2 certificate”: there's a report signed by a CPA.
- Type II requires an observation period, typically 3-12 months.
- Only the Security criterion is mandatory; the other four are optional.