Compliance & Certifications • SOC 2

What Is SOC 2?
A Guide for Industrial Buyers

Merobix Engineering • • 12 min read

"Are you SOC 2 certified?" is the most common security question cloud SCADA vendors hear - and it is technically a trick question, because SOC 2 is not a certification at all. It is an attestation: a licensed CPA firm's professional opinion on a vendor's controls, delivered as a detailed report you are supposed to actually read. This guide explains what SOC 2 covers and what it deliberately does not, the difference between Type I and Type II, the full path from scoping to report, honest timelines and cost ranges, how to read an auditor's opinion and its exceptions, and how SOC 2 fits next to ISO 27001 and IEC 62443 when you are buying industrial software.

Back to Blog

Part of the Merobix OT security guide collection - vendor vetting to industry compliance.

5Trust Services Criteria
2Report Types (I & II)
3–12Months, Type II Observation Window

Attestation, Not Certification: Why the Word Matters

SOC 2 comes from the AICPA - the American Institute of Certified Public Accountants - and it can only be performed by a licensed CPA firm. The firm does not "certify" anything. It attests: it examines management's description of the service organization's system and its controls, tests them against the Trust Services Criteria, and expresses a professional opinion in a written report. There is no certificate to hang on the wall, no accredited registry of SOC 2 holders, and no official badge - those checkmark logos on vendor websites are marketing artifacts, not issued credentials.

This matters practically, not just linguistically. Because the deliverable is a report rather than a pass/fail certificate, two vendors "with SOC 2" can be in wildly different shape - one with a clean opinion across five criteria, another with a qualified opinion, a narrow scope, and a page of exceptions. The report is where the truth lives, which is why sophisticated buyers always request it (vendors share it under NDA) instead of accepting the claim. When a vendor says "SOC 2 certified," it is at best imprecise shorthand; treat it as an invitation to ask for the document.

The Five Trust Services Criteria

A SOC 2 examination is scoped against up to five criteria families, defined in the AICPA's 2017 Trust Services Criteria (with revised points of focus, 2022). Security - also called the common criteria - is mandatory in every SOC 2 and covers access control, change management, risk management, monitoring, and incident response. The other four are optional and chosen to fit what the service does:

For a cloud SCADA vendor, the criteria set worth asking for is Security plus Availability plus Confidentiality. A Security-only scope is legitimate but tells you nothing about uptime discipline - and uptime discipline is much of what you are paying a monitoring platform for.

Type I vs Type II: Snapshot vs Track Record

Attribute SOC 2 Type I SOC 2 Type II
What it testsAre controls suitably designed?Were controls designed and operating effectively?
Time dimensionA single point in timeAn observation period, typically 3–12 months
Evidence testedDesign documentation, walkthroughsSampled operation across the window: access reviews done, changes approved, incidents handled, restores tested
Evidentiary weightMilestone; proves intent and designThe standard enterprise requirement; proves sustained operation
Typical roleFirst report while the Type II window runsRenewed annually with a fresh observation period

The sequence most vendors follow: readiness work, then a Type I as a first proof point, then a Type II covering the following observation window, then annual Type II renewals. When a vendor tells you "our Type II window closes in Q3," that is a normal, checkable statement of progress - the kind of specific answer our certification pillar guide teaches you to prefer over logo walls.

The Full SOC 2 Process, Start to Report

  1. Scoping. Define the system boundary (which products, infrastructure, teams) and select criteria. Scope gaming exists here too - confirm the platform you are buying is inside the boundary.
  2. Gap assessment. A readiness review - internal, consultant-led, or tooling-assisted - compares existing controls against the criteria and produces the remediation list.
  3. Remediation. Typically 3–6 months: writing and adopting policies, tightening access management, formalizing change control, standing up monitoring and evidence collection. Modern compliance platforms automate much of the evidence gathering.
  4. Observation window (Type II). Controls operate for 3–12 months while evidence accrues. Nothing shortcuts this; the window is the point.
  5. Fieldwork and audit. The CPA firm samples evidence, interviews staff, and tests each control - several weeks, usually.
  6. The report. Management's assertion, the auditor's opinion, the system description, and the control-by-control test results with any exceptions.

Timeline and Cost, Honestly

From a standing start to a first Type II report, expect roughly 9 to 18 months: 3–6 months of readiness, a 3–12 month window, then reporting. Costs vary too much for a single number to be honest: commonly cited audit fees range from the low tens of thousands of dollars for a small, Security-only scope to six figures for large multi-criteria examinations, and readiness tooling, consultants, and internal engineering time often match or exceed the audit fee. The expense is the credential: a Type II report cannot be bought quickly, which is precisely why procurement teams trust it.

How to Read a SOC 2 Report Like a Pro

When the PDF arrives under NDA, most buyers skim to the logo page. Read these four things instead:

SOC 1 vs SOC 2 vs SOC 3

Quick disambiguation, since RFPs confuse them constantly: SOC 1 covers controls relevant to a customer's financial reporting (payroll processors, billing platforms). SOC 2 covers security and operational trust criteria - the one that matters for SCADA. SOC 3 is a public, general-use summary of a SOC 2 examination with the detail stripped out; useful for websites, insufficient for diligence. Ask for the SOC 2, read the SOC 2.

Why SOC 2 Matters for Cloud SCADA - and Where It Stops

Your SCADA platform holds a privileged position: it sees your operational data, alerts your operators, and - where you enable control - writes setpoints to your process. SOC 2's criteria map directly onto the questions that position raises: who at the vendor can touch production, how changes reach the platform, whether monitoring would catch abuse, whether availability commitments are engineered or aspirational. That is why utilities, pipeline operators, and manufacturers increasingly require SOC 2 evidence from any SaaS vendor in the operational chain - the same buyers our enterprise SCADA buyer's guide is written for.

But SOC 2 stops at the service organization's edge. It does not evaluate device identity, telemetry signing, protocol security, setpoint bounds checking, or any of the OT-specific surface - for that layer the yardstick is IEC 62443, and internationally-minded buyers will also weigh ISO 27001 for the management system. The three are complements; our side-by-side comparison shows exactly which risk each one retires.

Where does Merobix stand? Honestly and specifically: Merobix is not SOC 2 attested today - it runs a SOC 2 readiness program, with control implementation and evidence collection underway, alongside a control mapping to IEC 62443 for the platform architecture. The controls themselves - MFA and passkeys, role and site-level authorization, tenant isolation enforced with row-level security, immutable audit records, signed telemetry, an outbound-only gateway - are shipped and demonstrable now, and independent penetration testing is part of the ongoing validation program. The full posture is documented on the security page. That is the shape of a trustworthy interim answer from any vendor: named framework, stated stage, verifiable controls today.

Key takeaway: SOC 2 is an attestation - a CPA firm's opinion delivered as a report, not a certificate - and its value is entirely in the details: Type II over Type I, Security plus Availability in scope, a clean opinion, few exceptions, and CUECs you actually implement. Require the report, not the badge; accept a specific readiness position from younger vendors; and pair SOC 2 with IEC 62443 evaluation, because no accountant's opinion has ever tested a PLC protocol.

Questions to Ask Any Cloud SCADA Vendor About SOC 2

  1. Do you have a SOC 2 report - Type I or Type II - and will you share it under NDA?
  2. Which Trust Services Criteria are in scope? Is availability included?
  3. What period does the report cover, and when does the next examination close?
  4. Were there exceptions, and what were the management responses?
  5. What CUECs does the report assign to customers like us?
  6. If no report yet: where are you in the readiness process, and what control evidence can you show today?

Then verify the answers against the running platform - request a demo and ask to see the audit trail, access controls, and alerting live. Paper plus architecture is the standard; either alone is half an answer.

Frequently Asked Questions

Is SOC 2 a certification or an attestation?

SOC 2 is an attestation, not a certification - the distinction is real, not pedantic. In a certification scheme like ISO 27001, an accredited body issues a certificate stating you met a standard. In a SOC 2 examination, a licensed CPA firm expresses a professional opinion on management's description of its system and the design (Type I) or design and operating effectiveness (Type II) of its controls against the AICPA Trust Services Criteria. The output is a detailed report, not a certificate, and there is no pass/fail registry. That is why careful buyers ask to read the report itself rather than accepting a SOC 2 badge on a website.

What is the difference between SOC 2 Type I and Type II?

A Type I report evaluates whether controls are suitably designed at a single point in time - a snapshot. A Type II report tests whether those controls actually operated effectively over an observation period, typically 3 to 12 months, with the auditor sampling evidence across the window: access reviews performed, changes approved, incidents handled, backups tested. Type II is substantially stronger evidence and is what most enterprise buyers require. Many vendors do a Type I first as a milestone while their Type II observation window runs, which is a legitimate and common sequence.

How long does SOC 2 take and how much does it cost?

Typical sequencing: a readiness and remediation phase of roughly 3 to 6 months (writing policies, closing control gaps, standing up evidence collection), then a Type II observation window of 3 to 12 months, then several weeks of fieldwork and reporting. Audit fees vary with scope and firm; commonly cited ranges run from the low tens of thousands of dollars for a focused Security-criteria audit at a small company to well over six figures for large scopes, before counting readiness tooling and internal effort. All figures vary - the durable point is that a Type II report represents at least two to three quarters of sustained work, which is what gives it evidentiary weight.

How do I read a SOC 2 report?

Go straight to four things. First, the auditor's opinion: unqualified (clean) versus qualified - a qualified opinion means at least one criterion was not met. Second, the scope: which Trust Services Criteria are covered (Security is mandatory; availability and confidentiality matter for SCADA) and which system boundary - confirm the product you are buying is inside it. Third, the exceptions: Section 4 lists every test and any deviations the auditor found; a handful of minor exceptions with management responses is normal, patterns in access control or change management are not. Fourth, the complementary user entity controls (CUECs) - the things the report assumes you, the customer, will do, such as enforcing MFA for your own users. Those become your obligations.

Does a cloud SCADA vendor need SOC 2?

If the vendor operates a cloud service that carries your operational data, SOC 2 (or ISO 27001 internationally) is the standard evidence that the operating organization is run with discipline - and most enterprise and utility procurement teams now require it or a credible readiness position. It is necessary but not sufficient: SOC 2 covers the service organization, not the industrial architecture, so pair it with IEC 62443-based evaluation of the platform itself. Newer vendors may legitimately be mid-journey; Merobix, for example, runs a SOC 2 readiness program with evidence collection underway and shares its control status openly rather than claiming a report it does not yet hold. What disqualifies a vendor is not the missing report - it is the inability to show controls and evidence at all.

Sources & Further Reading

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

Read Our Controls Before the Auditors Do

MFA, tenant isolation, immutable audit records, signed telemetry - the controls behind our SOC 2 readiness program are shipped and demonstrable today.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →