SOC 2 (System and Organization Controls 2) is a voluntary compliance framework developed by the AICPA, evaluating how service organisations manage customer data against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Only a licensed, independent CPA firm can perform the examination and issue a valid SOC 2 report — a distinct professional requirement, separate from ISO/IAF accreditation.
Why the CPA Firm Requirement Matters
SOC 2 examinations are exclusively carried out by licensed CPA firms operating under AICPA attestation standards (SSAE 18 and related AT-C sections). The auditing CPA firm must also be genuinely independent. This is a professional licensing requirement, not an accreditation scheme like IAF — the same category of restriction as an EU Notified Body for CE Marking, or NCSC CHECK for UK government penetration testing.
What London Cert genuinely brings to a SOC 2 engagement: control design and implementation work, gap assessment against the Trust Services Criteria, evidence collection processes, and audit-readiness preparation. We then facilitate the actual examination through an appropriately licensed CPA firm partner.
The Trust Services Criteria, in Brief
Security is mandatory in every SOC 2 examination — covering nine "Common Criteria" categories (CC1 through CC9). The other four criteria — Availability, Processing Integrity, Confidentiality, and Privacy — are optional, selected based on what you actually commit to customers in contracts and SLAs. The core criteria were established in 2017 and remain stable; the AICPA issued revised "points of focus" in 2022, and this remains current through 2026.
Type I vs Type II — A Real Difference
A Type I report assesses whether your controls are properly designed at a single point in time. A Type II report goes further, assessing whether those controls actually operated effectively over a review period — typically 6-12 months. Many organisations start with Type I to establish a baseline, then move to Type II for their first full annual report.
SOC 2's Relationship With ISO 27001
SOC 2 and ISO 27001 together account for the large majority of adopted security certifications and attestations among organisations pursuing customer trust credentials. They're genuinely complementary rather than competing: ISO 27001 is an IAF-accredited certification covering your whole ISMS; SOC 2 is a CPA-issued attestation typically scoped to a specific system or service, with particular weight in the US market.
Get SOC 2 Ready
Free consultation. We assess your current gaps and provide a fixed quote within 24 hours.
Get Free Quote →Also Need ISO 27001?
Genuinely IAF-accredited ISMS certification, often pursued alongside SOC 2.
Explore ISO 27001 →Related Pages
Real value of doing readiness work right
Based on outcomes reported by organisations we've prepared for SOC 2 examination.
Essential for US Enterprise Sales
SOC 2 is often a hard procurement requirement for selling SaaS and services into US enterprise customers.
US Market AccessSmoother CPA Examination
Thorough readiness work before your CPA firm engagement significantly reduces the risk of surfaced deficiencies.
Reduced Exam RiskScoped to What You Actually Need
We help you select only the Trust Services Criteria genuinely relevant to your service commitments.
Right-Sized ScopePairs Efficiently with ISO 27001
Significant control overlap between SOC 2 and ISO 27001 means combined readiness work reduces duplication.
Combined EfficiencyHonest About the CPA Requirement
We never imply we can issue your SOC 2 report ourselves — you know exactly what we do and what the CPA firm does.
No False ClaimsType II-Ready From the Start
We help you design controls and evidence collection processes that hold up over a full Type II review period.
Sustained ComplianceWhat businesses say about London Cert's SOC 2 readiness work
Feedback from organisations we've prepared for SOC 2 examination.
We didn't realize a CPA firm had to actually issue the report — London Cert explained this clearly upfront and did excellent groundwork before handing us off to their CPA partner.
Our Type II examination went smoothly because London Cert's readiness work meant our controls were already operating properly before the CPA firm's review period even started.
We combined our SOC 2 and ISO 27001 readiness work with London Cert — the overlap in controls was substantial and saved us real time and cost.
