BSTS markBSTS
All insights
6 min read

SOC 2 Readiness Is Not the Same as SOC 2 Certification

The two phrases get blurred constantly — sometimes innocently, sometimes not. What each one actually means, why the distinction is legally and commercially important, and how to buy readiness help without being misled.

This article is general information about security frameworks, not legal or audit advice. BSTS provides readiness support and is not a CPA firm or audit body.

If you buy technology services long enough, you will meet a vendor whose website says “SOC 2 compliant” in the footer, whose sales deck says “SOC 2 certified,” and whose actual status is that someone on the team once read the Trust Services Criteria. The gap between those statements is not pedantry. It determines what you can legally rely on.

What SOC 2 actually is

SOC 2 is a reporting framework from the AICPA — the American Institute of Certified Public Accountants — under which an independent, licensed CPA firm examines a service organization's controls against the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality, and privacy. The output is not a certificate. It is an attestation report — an auditor's written opinion, bound to a scope and a time frame.

  • A Type I report opines on the design of controls at a single point in time.
  • A Type II report opines on both design and operating effectiveness over a period, typically three to twelve months — which is why sophisticated buyers ask for Type II specifically.

Strictly speaking, then, there is no such thing as being “SOC 2 certified.” There are organizations holding a current attestation report with an unqualified opinion, and there is everyone else. The phrase “SOC 2 compliant” is looser still — SOC 2 is not a pass/fail standard you comply with, it is an examination you undergo.

What readiness actually is

Readiness work is everything an organization does before the auditors arrive: mapping existing practices to the Trust Services Criteria, closing gaps, writing the policies the audit will ask for, standing up evidence collection so proof accumulates as a byproduct of operations rather than a quarterly scramble, and often a readiness assessment — a rehearsal performed by a consultant.

Readiness is real, valuable work. A well-run readiness engagement is the difference between a smooth audit and an expensive one. But it produces preparation, not opinion. A consultant who prepared you cannot also attest you; independence rules exist precisely so the person grading the exam is not the person who coached for it.

Why the wording is worth policing

For buyers: a vendor's SOC 2 claim is only as good as the report behind it. Ask for the actual report under NDA. Check the period, the scope — which services and locations were examined — and the opinion. A report from three years ago, or one scoped to a product you do not use, tells you little.

For sellers: overstating status is not a marketing rounding error. Claiming a certification you do not hold invites regulatory attention for deceptive practices, breaches warranties you have probably signed in customer contracts, and — most practically — detonates trust at the exact moment a real prospect's security team asks for the report you implied exists.

The honest ladder

There is language for every honest rung, and using the right rung costs nothing:

  • “Our security practices are informed by the SOC 2 Trust Services Criteria” — legitimate from day one.
  • “We are pursuing SOC 2 readiness” — legitimate once the work has genuinely begun.
  • “We have completed a readiness assessment and are engaging an audit firm” — legitimate at that stage, and impressive in its precision.
  • “We hold a current SOC 2 Type II report, available under NDA” — the top rung, and the only rung that means an independent opinion exists.

Buyers reward the precision more than sellers expect. A small firm that says exactly where it stands on that ladder signals more security maturity than a large one with a vague badge.

BSTS provides SOC 2 readiness support — controls mapping, gap remediation, and evidence habits — and we describe it as exactly that. We are not a CPA firm, we do not issue attestation reports, and we will never describe readiness work as certification. The same discipline applies to every framework we reference, including NIST CSF 2.0.

Want this thinking applied to your operation?