SOC 2 compliance: a 10-step guide for mid-market companies.
A practical 10-step guide to SOC 2 for mid-market companies: scope, gap assessment, controls, evidence, choosing an auditor, and staying compliant.
SOC 2 compliance means having your security controls examined by an independent CPA firm against the AICPA Trust Services Criteria and receiving a SOC 2 report. For a mid-market company, the path takes ten steps: choose the report type, set the scope, run a gap assessment, fix gaps, document, check readiness, choose an auditor, go through the audit, respond to findings, and keep controls running for the next period.
What SOC 2 is, and why it matters
SOC 2 (System and Organization Controls 2) is a reporting framework from the American Institute of Certified Public Accountants (AICPA). It shows how a service organization protects customer data, measured against five Trust Services Criteria:
- Security: systems and data are protected from unauthorized access. Every SOC 2 includes it.
- Availability: systems are available as committed.
- Processing integrity: processing is complete, valid, accurate, and timely.
- Confidentiality: confidential information is protected as committed.
- Privacy: personal information is collected, used, and disposed of properly.
For mid-market companies, a SOC 2 report is often what moves an enterprise deal forward. It answers most of a customer's security questionnaire in one document and shows that an independent auditor has checked your controls.
Step 1: Choose the report type
A Type I report tests whether controls are designed well as of one date. A Type II report tests whether they worked over a period, usually 3 to 12 months. Many companies start with Type I and move to Type II. If your customers already ask for Type II, start the observation period as early as you can. See SOC 2 Type I vs. Type II.
Step 2: Set the scope
- Systems and services: which products, infrastructure, and data stores handle customer data.
- Criteria: Security is required. Add others when customer contracts or your service call for them, for example Availability for a platform with uptime commitments.
- Boundaries: which teams, locations, and subservice organizations (like your cloud provider) are in or out.
Keep the scope as tight as your customers allow. Every added system adds controls, evidence, and audit cost.
Step 3: Run a gap assessment
Compare what you do today with the criteria. Check that security policies exist and are approved, that access is based on roles and reviewed, that there is an incident response plan, that changes are approved and tested, that systems are monitored, and that vendors are assessed. List each gap with an owner and a date. See gap assessment.
Step 4: Close the gaps
Mid-market companies most often need to add or tighten these controls:
- MFA and SSO for workforce access, with least privilege.
- Encryption of data in transit and at rest.
- Logging and alerting for production systems.
- A documented change management process with peer review.
- Vulnerability scanning with fix deadlines by severity.
- Vendor risk reviews for providers that handle customer data.
- Security awareness training at hire and every year.
- Background checks where the law allows.
Automate where you can. A control that runs through your tools, like branch protection or automatic account deprovisioning, produces evidence on its own and fails less often.
Step 5: Write the documentation
Auditors will ask for your policies and procedures and a description of your system. The core set is an information security policy, access control, change management, incident response, business continuity and disaster recovery, vendor management, data classification and retention, and acceptable use. Write them to match what you do, with owners and review dates. A policy that describes a process nobody follows creates an exception.
Step 6: Check readiness
Before the auditor arrives, run a readiness assessment: test each control the way the auditor will, confirm evidence exists and is dated, and fix what is missing. Many companies do this with a consultant or a GRC platform. It is the cheapest point at which to find problems.
Step 7: Choose an auditor
- Only a licensed CPA firm can issue a SOC 2 report.
- Look for experience with companies of your size and industry.
- Ask how they handle evidence requests and how much of the work is remote.
- Ask for references, a sample timeline, and a fixed fee for the scope.
- Check that the firm's report is recognized by the customers you sell to.
Step 8: Go through the audit
For Type II, the auditor samples evidence from across the observation period. Expect interviews with control owners, requests for lists (new hires, terminations, changes, incidents) from which they pick samples, walkthroughs of key processes, and inspection of system settings. Good organization matters here: evidence that is already dated and linked to each criterion shortens fieldwork.
Step 9: Respond to findings
Exceptions are common in a first report. For each one, agree on the facts with the auditor, write a management response that explains the cause and the fix, and track the fix to completion. Customers read exceptions, so a clear response and a fixed control matter more than a perfect first report.
Step 10: Stay compliant
SOC 2 continues after the first report. Most companies move to back-to-back 12-month periods, so controls have to run all year. Keep evidence current, re-run your readiness checks every quarter, train new hires, review vendors, and update the scope when you launch new products or systems.
Common challenges for mid-market companies
| Challenge | What helps |
|---|---|
| No dedicated compliance team | Assign control owners in IT and engineering, and automate evidence collection |
| Competing priorities | Tie SOC 2 to specific deals and revenue so it gets time and budget |
| Evidence scattered across tools | One place where each piece of evidence is stored, dated, and linked to its criterion |
| Vendor risk | Tier vendors and review their SOC 2 reports as part of your own program |
| A second framework on the way | Map controls once so ISO 27001 or HIPAA reuse the same evidence |
How TruOps helps
TruOps pre-fills a SOC 2 readiness assessment from your documents, with a source behind every answer. It monitors technical controls through read-only connections to your cloud, identity, and code tools, keeps dated evidence for each criterion, and turns gaps into findings with recommended fixes. The same evidence maps to ISO 27001 and other frameworks, so your next framework starts partly done.
Questions
How long does SOC 2 take for a mid-market company?
Often 3 to 6 months to reach a Type I report, and 6 to 12 months to a first Type II report, depending on how many gaps you start with and the length of the observation period.
Is SOC 2 required by law?
No. SOC 2 is voluntary. Customers require it in contracts and security reviews, which makes it close to mandatory for many B2B software and service companies.
Which Trust Services Criteria should we include?
Security is required. Add Availability if you make uptime commitments, and Confidentiality or Privacy if customers ask or your service handles that kind of data. Many first reports cover Security alone.
Can we get SOC 2 and ISO 27001 at the same time?
Yes. The two overlap heavily. Mapping one set of controls to both lets you collect evidence once and run the audits close together.
Related
AICPA Trust Services Criteria: Type I and Type II readiness.
→Use casesSOC 2 readinessGo from documents to a SOC 2-ready program, with evidence attached.
→LearnSOC 2 Type I vs. Type IIDesign at a point in time vs. effectiveness over a period.
→Use casesAudit preparationWalk into fieldwork with dated, sourced evidence.
→See it run on your own data.
Book 30 minutes with a GRC specialist. Bring a real document, like a SOC 2 report, risk register, or vendor list (redacted is fine), and we'll show TruOps 2.0 working on it.