SOC 2 Readiness Is Not the Same as SOC 2 Certification
The two phrases get blurred constantly — sometimes innocently, sometimes not. What each one actually means, why the distinction is legally and commercially important, and how to buy readiness help without being misled.
This article is general information about security frameworks, not legal or audit advice. BSTS provides readiness support and is not a CPA firm or audit body.
If you buy technology services long enough, you will meet a vendor whose website says “SOC 2 compliant” in the footer, whose sales deck says “SOC 2 certified,” and whose actual status is that someone on the team once read the Trust Services Criteria. The gap between those statements is not pedantry. It determines what you can legally rely on.
What SOC 2 actually is
SOC 2 is a reporting framework from the AICPA — the American Institute of Certified Public Accountants — under which an independent, licensed CPA firm examines a service organization's controls against the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality, and privacy. The output is not a certificate. It is an attestation report — an auditor's written opinion, bound to a scope and a time frame.
- A Type I report opines on the design of controls at a single point in time.
- A Type II report opines on both design and operating effectiveness over a period, typically three to twelve months — which is why sophisticated buyers ask for Type II specifically.
Strictly speaking, then, there is no such thing as being “SOC 2 certified.” There are organizations holding a current attestation report with an unqualified opinion, and there is everyone else. The phrase “SOC 2 compliant” is looser still — SOC 2 is not a pass/fail standard you comply with, it is an examination you undergo.
What readiness actually is
Readiness work is everything an organization does before the auditors arrive: mapping existing practices to the Trust Services Criteria, closing gaps, writing the policies the audit will ask for, standing up evidence collection so proof accumulates as a byproduct of operations rather than a quarterly scramble, and often a readiness assessment — a rehearsal performed by a consultant.
Readiness is real, valuable work. A well-run readiness engagement is the difference between a smooth audit and an expensive one. But it produces preparation, not opinion. A consultant who prepared you cannot also attest you; independence rules exist precisely so the person grading the exam is not the person who coached for it.
Why the wording is worth policing
For buyers: a vendor's SOC 2 claim is only as good as the report behind it. Ask for the actual report under NDA. Check the period, the scope — which services and locations were examined — and the opinion. A report from three years ago, or one scoped to a product you do not use, tells you little.
For sellers: overstating status is not a marketing rounding error. Claiming a certification you do not hold invites regulatory attention for deceptive practices, breaches warranties you have probably signed in customer contracts, and — most practically — detonates trust at the exact moment a real prospect's security team asks for the report you implied exists.
The honest ladder
There is language for every honest rung, and using the right rung costs nothing:
- “Our security practices are informed by the SOC 2 Trust Services Criteria” — legitimate from day one.
- “We are pursuing SOC 2 readiness” — legitimate once the work has genuinely begun.
- “We have completed a readiness assessment and are engaging an audit firm” — legitimate at that stage, and impressive in its precision.
- “We hold a current SOC 2 Type II report, available under NDA” — the top rung, and the only rung that means an independent opinion exists.
Buyers reward the precision more than sellers expect. A small firm that says exactly where it stands on that ladder signals more security maturity than a large one with a vague badge.
Want this thinking applied to your operation?