7 Myths About SOC 2 Compliance | Blog | OneTrust
7 Myths About SOC 2 Compliance
Understand what your company needs to achieve SOC 2 compliance and keep your customer data protected
Katrina Dalao
Sr. Content Marketing Specialist, CIPM, CIPP/E
February 27, 2024
Table of contents
- [1. SOC 2 is a certification](/content/blog/soc-2-compliance-myths/#myth-1 "1. SOC 2 is a certification"/index.html)
- [2. Auditors want to find issues](/content/blog/soc-2-compliance-myths/#myth-2 "2. Auditors want to find issues"/index.html)
- [3. SOC 2 is not worth the cost](/content/blog/soc-2-compliance-myths/#myth-3 "3. SOC 2 is not worth the cost"/index.html)
- [4. SOC 2 is a checklist of required controls](/content/blog/soc-2-compliance-myths/#myth-4 "4. SOC 2 is a checklist of required controls"/index.html)
- [5. SOC 2 only covers technical processes](/content/blog/soc-2-compliance-myths/#myth-5 "5. SOC 2 only covers technical processes"/index.html)
- [6. You can use your service provider’s report](/content/blog/soc-2-compliance-myths/#myth-6 "6. You can use your service provider’s report"/index.html)
- [7. A SOC 2 report can be done in a few weeks](/content/blog/soc-2-compliance-myths/#myth-7 "7. A SOC 2 report can be done in a few weeks"/index.html)
1. SOC 2 Is a Certification
Of all the SOC 2 myths out there, this is one of the most prevalent.
SOC 2 is not a certification, but a report on a company’s compliance efforts.
Once a SOC 2 audit is complete, the auditor will issue the company a report with an analysis of whether its operations are SOC 2 compliant.
Since an auditor can only determine a company’s compliance over the audit assessment period, it’s recommended to get your SOC 2 audit on an annual basis.
Compliance is assessed according to the following five Trust Services Criteria (TSC): security, availability, processing integrity, confidentiality, and privacy. Of the five criteria, however, security is the only required TSC to meet SOC 2 compliance.
2. Auditors Want to Find Issues
It’s a popular opinion that auditors are only looking for issues within your company.
However, while audits by nature examine every operational detail, companies and auditors want the same thing — to ensure the security of customer data. A secure company benefits everyone, and most auditors want companies to pass their audit.
That said, you shouldn’t hire any auditor without a thorough vetting process. You will work extensively with this individual and trust them with important company details. Select an auditor who aligns with your work ethic and understands your specific needs.
3. SOC 2 Is Not Worth the Cost
Today’s clients are increasingly invested in a company’s data privacy and protection measures. Before even considering a purchase, it’s common for clients to request a SOC 2 report as evidence of security compliance.
Aside from facilitating client sales, SOC 2 compliance serves as a competitive advantage and builds trust in your company’s reputation.
While it can be difficult to quantify the exact value of SOC 2 compliance, an annual report demonstrates your company’s effort to protect personal data and can effectively bring in new business.
4. SOC 2 Is a Checklist of Required Controls
Rather than a checklist of defined controls, SOC 2 audits are based on general objectives or criteria that gives companies more flexibility in how they choose to achieve compliance.
For instance, a company’s customer support training can meet both the availability and confidentiality criteria.
An auditor’s control list depends on the specific company and the controls they put in place to meet their determined objectives.
5. SOC 2 Only Covers Technical Processes
While many SOC 2 criteria fall under technical and software-related processes, they are not the only areas covered by the audit.
SOC 2 also encompasses COSO, a framework that includes the following components:
- Control environment
- Risk assessment
- Information and communication
- Existing control activities
- Monitoring activities
SOC 2 is a comprehensive examination that looks at a company’s overall infrastructure to determine a complete and trusted governance structure.
6. Companies Can Use Their Service Provider’s SOC 2 Report
All companies need to go through their own audit to get a SOC 2 report. Even if their software applications are hosted by another company that’s SOC 2 compliant, such as AWS or Microsoft Azure, every company is responsible for their own compliance.
The shared responsibility model recognizes that different companies implement their own set of controls and will therefore need to secure their own SOC 2 report.
7. A SOC 2 Report Can Be Done in a Few Weeks
A company can only begin a SOC 2 audit after its controls have been implemented for at least a few weeks. Furthermore, an auditor can take several months to review all systems and create a report.
While the total audit duration depends on several factors, it’s unlikely a SOC 2 report will be ready in less than a month.
It takes time to build a reliable security program, as well as document the entire company’s procedures and policies needed for SOC 2 compliance.
Learn more about achieving SOC 2 compliance in our Ultimate survival guide to SOC 2 compliance, where we break down the exact steps to reduce your level of effort, shorten your timelines, and focus on what really matters.