What Is SOC 2?
A Guide for Industrial Buyers
"Are you SOC 2 certified?" is the most common security question cloud SCADA vendors hear - and it is technically a trick question, because SOC 2 is not a certification at all. It is an attestation: a licensed CPA firm's professional opinion on a vendor's controls, delivered as a detailed report you are supposed to actually read. This guide explains what SOC 2 covers and what it deliberately does not, the difference between Type I and Type II, the full path from scoping to report, honest timelines and cost ranges, how to read an auditor's opinion and its exceptions, and how SOC 2 fits next to ISO 27001 and IEC 62443 when you are buying industrial software.
Part of the Merobix OT security guide collection - vendor vetting to industry compliance.
Attestation, Not Certification: Why the Word Matters
SOC 2 comes from the AICPA - the American Institute of Certified Public Accountants - and it can only be performed by a licensed CPA firm. The firm does not "certify" anything. It attests: it examines management's description of the service organization's system and its controls, tests them against the Trust Services Criteria, and expresses a professional opinion in a written report. There is no certificate to hang on the wall, no accredited registry of SOC 2 holders, and no official badge - those checkmark logos on vendor websites are marketing artifacts, not issued credentials.
This matters practically, not just linguistically. Because the deliverable is a report rather than a pass/fail certificate, two vendors "with SOC 2" can be in wildly different shape - one with a clean opinion across five criteria, another with a qualified opinion, a narrow scope, and a page of exceptions. The report is where the truth lives, which is why sophisticated buyers always request it (vendors share it under NDA) instead of accepting the claim. When a vendor says "SOC 2 certified," it is at best imprecise shorthand; treat it as an invitation to ask for the document.
The Five Trust Services Criteria
A SOC 2 examination is scoped against up to five criteria families, defined in the AICPA's 2017 Trust Services Criteria (with revised points of focus, 2022). Security - also called the common criteria - is mandatory in every SOC 2 and covers access control, change management, risk management, monitoring, and incident response. The other four are optional and chosen to fit what the service does:
- Availability - the system is available as committed: capacity planning, monitoring, backup and recovery, incident handling. Highly relevant to SCADA, where the availability of alarms and telemetry is the product.
- Processing integrity - processing is complete, accurate, timely, and authorized. Relevant where the platform computes and transforms operational data.
- Confidentiality - information designated confidential is protected through its lifecycle, from encryption to disposal.
- Privacy - personal information handling; often less central for industrial telemetry platforms than for consumer services.
For a cloud SCADA vendor, the criteria set worth asking for is Security plus Availability plus Confidentiality. A Security-only scope is legitimate but tells you nothing about uptime discipline - and uptime discipline is much of what you are paying a monitoring platform for.
Type I vs Type II: Snapshot vs Track Record
| Attribute | SOC 2 Type I | SOC 2 Type II |
|---|---|---|
| What it tests | Are controls suitably designed? | Were controls designed and operating effectively? |
| Time dimension | A single point in time | An observation period, typically 3–12 months |
| Evidence tested | Design documentation, walkthroughs | Sampled operation across the window: access reviews done, changes approved, incidents handled, restores tested |
| Evidentiary weight | Milestone; proves intent and design | The standard enterprise requirement; proves sustained operation |
| Typical role | First report while the Type II window runs | Renewed annually with a fresh observation period |
The sequence most vendors follow: readiness work, then a Type I as a first proof point, then a Type II covering the following observation window, then annual Type II renewals. When a vendor tells you "our Type II window closes in Q3," that is a normal, checkable statement of progress - the kind of specific answer our certification pillar guide teaches you to prefer over logo walls.
The Full SOC 2 Process, Start to Report
- Scoping. Define the system boundary (which products, infrastructure, teams) and select criteria. Scope gaming exists here too - confirm the platform you are buying is inside the boundary.
- Gap assessment. A readiness review - internal, consultant-led, or tooling-assisted - compares existing controls against the criteria and produces the remediation list.
- Remediation. Typically 3–6 months: writing and adopting policies, tightening access management, formalizing change control, standing up monitoring and evidence collection. Modern compliance platforms automate much of the evidence gathering.
- Observation window (Type II). Controls operate for 3–12 months while evidence accrues. Nothing shortcuts this; the window is the point.
- Fieldwork and audit. The CPA firm samples evidence, interviews staff, and tests each control - several weeks, usually.
- The report. Management's assertion, the auditor's opinion, the system description, and the control-by-control test results with any exceptions.
Timeline and Cost, Honestly
From a standing start to a first Type II report, expect roughly 9 to 18 months: 3–6 months of readiness, a 3–12 month window, then reporting. Costs vary too much for a single number to be honest: commonly cited audit fees range from the low tens of thousands of dollars for a small, Security-only scope to six figures for large multi-criteria examinations, and readiness tooling, consultants, and internal engineering time often match or exceed the audit fee. The expense is the credential: a Type II report cannot be bought quickly, which is precisely why procurement teams trust it.
How to Read a SOC 2 Report Like a Pro
When the PDF arrives under NDA, most buyers skim to the logo page. Read these four things instead:
- The opinion. "Unqualified" is clean. "Qualified" means the auditor found at least one criterion not met - read the qualification carefully; it is sometimes narrow and explainable, sometimes damning.
- The scope and period. Which criteria, which system, which dates. A report on a different product line, or one whose period ended eighteen months ago, is weaker evidence than it looks.
- Exceptions in the test results. Section 4 lists every control tested and every deviation. A few isolated exceptions with credible management responses are normal in real organizations; repeated exceptions in access control or change management are a pattern, and patterns are the finding.
- CUECs - complementary user entity controls. The report assumes you will do certain things: enforce MFA for your users, manage your own user offboarding, configure alerting appropriately. These silently become your responsibility; put them in your runbook. This is the paper version of the shared-responsibility conversation every cloud SCADA buyer should have anyway.
SOC 1 vs SOC 2 vs SOC 3
Quick disambiguation, since RFPs confuse them constantly: SOC 1 covers controls relevant to a customer's financial reporting (payroll processors, billing platforms). SOC 2 covers security and operational trust criteria - the one that matters for SCADA. SOC 3 is a public, general-use summary of a SOC 2 examination with the detail stripped out; useful for websites, insufficient for diligence. Ask for the SOC 2, read the SOC 2.
Why SOC 2 Matters for Cloud SCADA - and Where It Stops
Your SCADA platform holds a privileged position: it sees your operational data, alerts your operators, and - where you enable control - writes setpoints to your process. SOC 2's criteria map directly onto the questions that position raises: who at the vendor can touch production, how changes reach the platform, whether monitoring would catch abuse, whether availability commitments are engineered or aspirational. That is why utilities, pipeline operators, and manufacturers increasingly require SOC 2 evidence from any SaaS vendor in the operational chain - the same buyers our enterprise SCADA buyer's guide is written for.
But SOC 2 stops at the service organization's edge. It does not evaluate device identity, telemetry signing, protocol security, setpoint bounds checking, or any of the OT-specific surface - for that layer the yardstick is IEC 62443, and internationally-minded buyers will also weigh ISO 27001 for the management system. The three are complements; our side-by-side comparison shows exactly which risk each one retires.
Where does Merobix stand? Honestly and specifically: Merobix is not SOC 2 attested today - it runs a SOC 2 readiness program, with control implementation and evidence collection underway, alongside a control mapping to IEC 62443 for the platform architecture. The controls themselves - MFA and passkeys, role and site-level authorization, tenant isolation enforced with row-level security, immutable audit records, signed telemetry, an outbound-only gateway - are shipped and demonstrable now, and independent penetration testing is part of the ongoing validation program. The full posture is documented on the security page. That is the shape of a trustworthy interim answer from any vendor: named framework, stated stage, verifiable controls today.
Key takeaway: SOC 2 is an attestation - a CPA firm's opinion delivered as a report, not a certificate - and its value is entirely in the details: Type II over Type I, Security plus Availability in scope, a clean opinion, few exceptions, and CUECs you actually implement. Require the report, not the badge; accept a specific readiness position from younger vendors; and pair SOC 2 with IEC 62443 evaluation, because no accountant's opinion has ever tested a PLC protocol.
Questions to Ask Any Cloud SCADA Vendor About SOC 2
- Do you have a SOC 2 report - Type I or Type II - and will you share it under NDA?
- Which Trust Services Criteria are in scope? Is availability included?
- What period does the report cover, and when does the next examination close?
- Were there exceptions, and what were the management responses?
- What CUECs does the report assign to customers like us?
- If no report yet: where are you in the readiness process, and what control evidence can you show today?
Then verify the answers against the running platform - request a demo and ask to see the audit trail, access controls, and alerting live. Paper plus architecture is the standard; either alone is half an answer.
Frequently Asked Questions
Is SOC 2 a certification or an attestation?
SOC 2 is an attestation, not a certification - the distinction is real, not pedantic. In a certification scheme like ISO 27001, an accredited body issues a certificate stating you met a standard. In a SOC 2 examination, a licensed CPA firm expresses a professional opinion on management's description of its system and the design (Type I) or design and operating effectiveness (Type II) of its controls against the AICPA Trust Services Criteria. The output is a detailed report, not a certificate, and there is no pass/fail registry. That is why careful buyers ask to read the report itself rather than accepting a SOC 2 badge on a website.
What is the difference between SOC 2 Type I and Type II?
A Type I report evaluates whether controls are suitably designed at a single point in time - a snapshot. A Type II report tests whether those controls actually operated effectively over an observation period, typically 3 to 12 months, with the auditor sampling evidence across the window: access reviews performed, changes approved, incidents handled, backups tested. Type II is substantially stronger evidence and is what most enterprise buyers require. Many vendors do a Type I first as a milestone while their Type II observation window runs, which is a legitimate and common sequence.
How long does SOC 2 take and how much does it cost?
Typical sequencing: a readiness and remediation phase of roughly 3 to 6 months (writing policies, closing control gaps, standing up evidence collection), then a Type II observation window of 3 to 12 months, then several weeks of fieldwork and reporting. Audit fees vary with scope and firm; commonly cited ranges run from the low tens of thousands of dollars for a focused Security-criteria audit at a small company to well over six figures for large scopes, before counting readiness tooling and internal effort. All figures vary - the durable point is that a Type II report represents at least two to three quarters of sustained work, which is what gives it evidentiary weight.
How do I read a SOC 2 report?
Go straight to four things. First, the auditor's opinion: unqualified (clean) versus qualified - a qualified opinion means at least one criterion was not met. Second, the scope: which Trust Services Criteria are covered (Security is mandatory; availability and confidentiality matter for SCADA) and which system boundary - confirm the product you are buying is inside it. Third, the exceptions: Section 4 lists every test and any deviations the auditor found; a handful of minor exceptions with management responses is normal, patterns in access control or change management are not. Fourth, the complementary user entity controls (CUECs) - the things the report assumes you, the customer, will do, such as enforcing MFA for your own users. Those become your obligations.
Does a cloud SCADA vendor need SOC 2?
If the vendor operates a cloud service that carries your operational data, SOC 2 (or ISO 27001 internationally) is the standard evidence that the operating organization is run with discipline - and most enterprise and utility procurement teams now require it or a credible readiness position. It is necessary but not sufficient: SOC 2 covers the service organization, not the industrial architecture, so pair it with IEC 62443-based evaluation of the platform itself. Newer vendors may legitimately be mid-journey; Merobix, for example, runs a SOC 2 readiness program with evidence collection underway and shares its control status openly rather than claiming a report it does not yet hold. What disqualifies a vendor is not the missing report - it is the inability to show controls and evidence at all.
Sources & Further Reading
- SOC 2 - SOC for Service Organizations - AICPA & CIMA
- 2017 Trust Services Criteria (With Revised Points of Focus - 2022) - AICPA & CIMA
- SOC 3 - Trust Services Criteria for General Use Report - AICPA & CIMA
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.