Skip to main contentChat with us

Learn · SOC Reports

Is There a SOC 2
Certificate?

No. There is no SOC 2 certificate, no SOC 2 certification body, and no register of certified organizations for a buyer to look you up in. A SOC 2 engagement produces one thing: an independent licensed CPA firm's attestation report, containing an opinion, covering a stated system and a stated period.

Certification and attestation are different instruments. ISO/IEC 27001 is a certification — a certification body, normally accredited, audits your management system and issues a certificate with an expiry date. SOC 2 is an examination under AT-C 205 that ends in an opinion. Borrowing one vocabulary for the other is how vendors lose credibility in a security review they were otherwise winning.

0SOC 2 certificates in existence
AT-C 205standard behind the opinion
250+SOC 2 engagements supported by TCSA

Plain-English explainer · AT-C 105 & AT-C 205 · AICPA SOC logo terms · Last reviewed August 2026

There is no SOC 2 certificate. SOC 2 is an attestation examination performed by an independent licensed CPA firm under the AICPA’s attestation standards — AT-C section 105 and AT-C section 205 — and the deliverable is a report carrying an opinion on management’s description of its system and on the suitability of design (and, in a Type 2, operating effectiveness) of controls against the applicable trust services criteria. What you hold at the end is a document with an opinion paragraph and a service auditor’s signature. It has a period, a report date, and a restriction on who may read it. It has no certificate number, no expiry date, and no issuing authority beyond the firm that signed it. Nobody is accredited to certify against SOC 2, because there is nothing to be accredited to do: the AICPA writes the standards and criteria, and stops there. For the document itself, read how to read a SOC 2 report; for who may perform the work, see who can perform a SOC 2 audit.

What actually exists

Three real artifacts, and the vocabulary that goes with each report

The report

Five sections — the opinion, management’s assertion, the system description prepared under DC section 200, the controls-and-tests matrix, and optional unaudited information.

The opinion

Unmodified, qualified, adverse or disclaimed — an opinion on a description and on controls, never a grant of status to the organization.

The AICPA SOC logo

A marketing mark licensed to service organizations that register with the AICPA and hold a SOC 1, SOC 2 or SOC 3 report that does not contain a modified opinion. Permission to display an image, not a finding.

Which of those three you hold, and what you may therefore say, depends on the report family and the type. A Type 1 and a Type 2 are not interchangeable claims, and only one of the five rows below may be published without an NDA. Find your row before you write your trust page.

SOC 1 Type 1

Examined under AT-C section 320: an opinion on management’s description of the system and on the suitability of the design of controls relevant to user entities’ internal control over financial reporting, as of one date. No operating-effectiveness testing.

“SOC 1 Type 1 report as of 30 June 2026, reported on by [CPA firm].” Say Type 1 out loud — a reader who is not told assumes Type 2.

Restricted use: management, user entities and their auditors.

SOC 1 Type 2

The same subject matter under AT-C section 320, plus operating effectiveness across a stated period, with the tests and results set out in the report.

“SOC 1 Type 2 examination covering 1 January – 30 June 2026, reported on by [CPA firm].”

Restricted use: management, user entities and their auditors.

SOC 2 Type 1

An opinion on the description and on the suitability of design of controls against the applicable trust services criteria, as of one date. Nothing is sampled, because there is no period to sample.

“SOC 2 Type 1 report as of 30 June 2026 covering security and availability, reported on by [CPA firm]; Type 2 examination underway for the period beginning 1 July 2026.”

Restricted use: user entities, their auditors, and others with sufficient understanding of the system and the criteria.

SOC 2 Type 2

Design and operating effectiveness across a stated period, against the applicable trust services criteria, with the tests and results set out in Section 4.

“SOC 2 Type 2 examination completed for 1 January – 30 June 2026, unmodified opinion, reported on by [CPA firm]; report available under NDA.”

Restricted use: user entities, their auditors, and others with sufficient understanding of the system and the criteria.

SOC 3

A general-use report produced from the same SOC 2 examination: the practitioner’s opinion, management’s assertion, and a short management-prepared system description.

“SOC 3 report published here.” It is the only one of the five you may hand to anyone who asks.

General use — publish it. No restricted-use alert, no NDA, no gatekeeping.

None of the five is a certificate, and no row acquires one by being repeated. The family distinctions are unpacked in the types of SOC reports.

The precise contrast

ISO 27001 certification vs SOC 2 attestation

Not two flavors of one thing: two conformity-assessment instruments, from different organizations, under different rulebooks, with different lifecycles. Neither is superior and many companies hold both — scoping trade-offs are in our SOC 2 vs ISO 27001 guide. This table is about why the words are not interchangeable.

Who issues it

A certification body — a separate firm, ideally accredited by a national accreditation body (UKAS, ANAB, NABCB) signatory to the IAF arrangement.

An independent licensed CPA firm you engage. No accreditation scheme exists for SOC work; the controls are CPA licensing, independence and peer review.

Rules the issuer works under

ISO/IEC 17021-1 for certification bodies, plus ISO/IEC 27006-1:2024 for ISMS certification specifically.

AT-C section 105 and AT-C section 205 (assertion-based examination engagements), as amended by SSAE 21 and SSAE 23, plus the AICPA SOC 2 guide.

Criteria applied

ISO/IEC 27001 clauses 4–10, with Annex A controls selected and justified in a Statement of Applicability.

The applicable trust services criteria in TSP section 100 (2017 criteria, points of focus revised 2022) and the description criteria in DC section 200.

The artifact

A certificate: organization, scope statement, standard, certificate number, issue and expiry dates, accreditation mark. The audit report stays internal.

A report — typically 60–150+ pages (market practice; no standard sets a length): the opinion, management’s assertion, the system description, the controls-and-tests matrix, optional unaudited information.

How long it lasts

A three-year cycle under ISO/IEC 17021-1: first surveillance audit within twelve months of the certification decision, surveillance at least annually, then recertification.

Nothing expires. The report covers one stated historical period; buyers, not the AICPA, decide when it is stale — buyer convention, not a rule, is roughly twelve months past the period end.

Independent verification

Usually possible: the certification body keeps a client directory, and many accredited certificates are searchable via IAF CertSearch where the body participates.

None. The AICPA publishes no register of report holders. Verification means reading the report, which is restricted-use and travels under NDA.

Vocabulary for problems

Nonconformities, graded major or minor, closed by corrective action before the certificate is issued or maintained.

Exceptions, described in Section 4 with management’s response, and — if significant enough — a modified opinion: qualified, adverse or disclaimed.

What you may claim

“Certified to ISO/IEC 27001:2022 for [scope] by [body], certificate no. X, valid to [date].” Display the body’s mark, never the ISO logo.

“SOC 2 Type 2 examination completed for [period], reported on by [CPA firm]; report available under NDA.” The AICPA SOC logo may be displayed under its terms.

One detail from the ISO column travels back usefully. Even certified organizations may not display the ISO logo — ISO certifies nobody and does not license its mark for that purpose; you display your certification body’s mark. The pattern holds on both sides: the standards-setter is not the issuer. That is what rules out “audited by the AICPA”.

Why the word costs you

What a reviewer infers

The word rarely sinks a review on its own. The cost is quieter, and it lands in three places.

It changes what the reviewer expects to find.

The claim is not read on your homepage. It is read in the certification field of a CAIQ or SIG Lite response, on a Whistic, Vanta or Drata trust-center tile, or in a cloud marketplace listing — places where the reviewer’s next action is a request, not a purchase. Seeing “certified” there, the reviewer asks for the report cover page and Section 4 rather than accepting the tile, because anyone who has read a SOC 2 report knows it opens with an opinion and ends with exceptions.

It creates contract language you cannot satisfy.

Security exhibits inherit the vendor’s vocabulary, and two clause patterns do the damage. “Supplier shall maintain SOC 2 certification throughout the term” obliges you to hold a status that does not exist. “Supplier shall provide its current SOC 2 certificate annually” is the harder failure, because it names a deliverable that will never be produced — and it surfaces at renewal, or mid-incident, when nobody is in the mood to renegotiate definitions.

It sets the wrong renewal model internally.

Certificates run on multi-year cycles with surveillance in between; reports cover consecutive periods and need evidence collected while they run. Teams who believe they hold a certificate discover in month ten that nothing was collected for months one through nine of the current period. That gap cannot be closed retrospectively, because the population for an operating-effectiveness test is the period itself — there is no artifact you can manufacture in month ten that shows the control ran in month two.

Approved wording

What not to say, and what to say instead

For websites, security questionnaires, RFP responses and sales decks. Dates are illustrative — substitute your own period and name your own CPA firm.

“We are SOC 2 certified.”

“SOC 2 Type 2 examination completed for 1 January – 30 June 2026, reported on by an independent licensed CPA firm.”

No certificate exists to hold. The replacement is checkable: type, period, and who did the work.

“SOC 2 certification” (as a noun)

“SOC 2 attestation report” or “SOC 2 examination”

Certification is a conformity-assessment activity with an issuing body behind it. Attestation is what a CPA firm does under AT-C 205.

“Our SOC 2 certificate expires in June 2027.”

“The current report covers the period ending 30 June 2026; the next period ends 30 June 2027.”

Nothing expires, so an expiry date is unsupportable. Two real dates answer the question better than one invented one.

“We are SOC 2 compliant.”

“Our controls were examined against the trust services criteria for security, availability and confidentiality, with an unmodified opinion.”

Less wrong, still imprecise: there is no SOC 2 rulebook. The criteria are outcome-based and each organization designs its own controls.

“Audited and certified by the AICPA.”

“Examined by [CPA firm] under the AICPA’s attestation standards.”

The AICPA writes the standards and criteria. It performs no examinations and has no relationship with your organization.

“SOC 2 accredited” / “SOC 2 approved”

“SOC 2 Type 2 reported on for [period]”

Accreditation is what an accreditation body does to a certification body. It has no meaning where nobody accredits anyone.

“We passed our SOC 2 audit.”

“The report carries an unmodified opinion.”

There is no pass mark — there are four opinion outcomes, and exceptions can sit in Section 4 beneath a clean opinion.

“SOC 2 certified since 2023.”

“Successive SOC 2 examinations since 2023; most recent period 1 January – 30 June 2026.”

Continuity is a real claim — built from consecutive periods rather than a certificate date.

“SOC 2 Level 2” / “SOC Type 3”

“SOC 2 Type 2” — and, if you publish one, “SOC 3”

Two types, and three report families under SOC for Service Organizations — SOC 1, SOC 2, SOC 3; the wider AICPA SOC suite also holds SOC for Cybersecurity and SOC for Supply Chain. Invented labels prompt a reviewer to check everything else you wrote.

“Download our SOC 2 report” on a public page

“SOC 2 report available under NDA. SOC 3 report published here.”

The SOC 2 report is restricted-use. SOC 3 is the general-use report designed to be distributed freely.

One more phrase is worth fixing before it reaches a customer: “SOC 2 audit in progress”. It is legitimate and often the right thing to say, but it needs a period and a milestone attached — the framing is in what to tell customers while your SOC 2 is in progress.

Worked example

One vendor, one RFP, one bad field

Illustrative. The vendor completes its first Type 2 covering 1 January – 30 June 2026; the CPA firm signs an unmodified opinion and dates the report 12 August 2026. On 3 September 2026 an insurer’s procurement portal opens with six fields in its security annex.

Certification held

“SOC 2 certified”

“SOC 2 Type 2 — attestation report under AICPA standards, issued by an independent licensed CPA firm; not a certification.”

Certificate number

An invented reference, or the CPA firm’s engagement number passed off as one

“Not applicable — SOC 2 produces a report. Available under NDA.”

Issuing body

“AICPA”

“[CPA firm], independent licensed CPA firm”

Issue date

The date the program started

The report date — when the auditor signed the opinion: 12 August 2026

Expiry date

Report date plus twelve months, entered as fact

30 June 2026 (period end), noted: “no expiry applies; next period ends 30 June 2027”. If the portal validates the field and rejects a past date, enter the next period end instead and say so in the same note — never a date derived from the report date, which implies an expiry that does not exist.

Scope

“The whole company”

The system boundary per Section 3, plus the categories in scope

Everything turns on the certificate-number field. Here is what the invented reference actually costs, day by day.

3 September 2026

The vendor submits the insurer’s security annex. The certificate-number field is filled with an invented reference and the expiry field with the report date plus twelve months.

9 September 2026

The insurer’s risk analyst requests a copy of the certificate the reference points to.

12 September 2026

The vendor concedes that no certificate exists, and offers the report instead.

19 September 2026

The file is reopened and a correction to the supplier’s security representations is recorded against it — a note that outlives the deal.

26 September 2026

The NDA that should have been signed on 3 September is signed, and the report is finally sent.

Three weeks and a permanent note in the file, on a field that took ten seconds to answer correctly. The counterfactual is short: “not applicable — SOC 2 produces a report; available under NDA” returns an NDA inside the same week and the report the day after it is signed, which is what the field existed to produce.

Two later dates come out of the same facts. Logo permission runs to 12 August 2027, twelve months from the report date. Buyer freshness runs from the period end, putting this vendor into “send us the current one” territory around 30 June 2027. So the second period starts 1 July 2026 and the reports abut — the mechanic is in how long a SOC 2 report is valid.

Then the insurer’s security exhibit requires the vendor to “maintain SOC 2 certification for the term”. A redline that typically lands, because it gives the buyer something more testable than the word it replaced, is set out verbatim in Copy these further down this page.

The badge rules

Who may display the AICPA SOC logo

There is a legitimate mark, with terms attached. The AICPA runs separate logo programs for service organizations and for CPA firms; both require registration before the artwork may be downloaded or displayed.

Service organizations

The SOC for Service Organizations logo — the badge on vendor trust pages.

Open to an organization that has had a SOC 1, SOC 2 or SOC 3 report that does not contain a modified opinion issued by a licensed CPA. Registration is required; the artwork may be used only in the form supplied and altered only in size; it must be hyperlinked to the AICPA’s SOC page, or that URL shown nearby in print. Rights cannot be sublicensed, and the AICPA may ask to inspect materials bearing the logo.

CPA firms

A separate SOC logo for CPAs performing the examinations.

Restricted to licensed CPAs and CPA firms performing SOC 1, SOC 2 and SOC 3 examinations, on their own registration. A service organization may not use it, or the AICPA’s corporate logo, to imply professional status it does not hold.

Everyone else

Advisors, readiness partners, compliance platforms, resellers.

No entitlement to the service organization logo, which belongs to the organization named in a report. A firm that helped you prepare — including ours — does not display your badge as its own credential.

The condition most often missed is the clock: display is permitted for twelve months following the date of the report, and if no new report has been issued by then, use must stop. That makes the badge a maintenance obligation someone has to own — put the removal date in the compliance calendar beside the next observation period.

The eligibility bar has a consequence worth stating plainly: a qualified, adverse or disclaimed opinion removes logo eligibility even though the examination was completed and a real report exists. Finishing the engagement is not the test — the opinion is. The AICPA has revised these terms more than once, so read the version you accept at registration.

And the badge is not evidence: it licenses an image and says nothing about the type, the period, the categories in scope, or the opinion. Where a public badge is doing real sales work, the stronger artifact is often a SOC 3 report — a general-use report from the same examination, which you may publish freely.

Restricted use

What the report says about sharing it

The attestation standards require an alert when a report is intended only for specified parties, and SOC reports carry one. In a SOC 2 the restriction covers user entities, their auditors, and others with sufficient understanding of the service organization, its system, the criteria and the inherent limitations of controls. In a SOC 1 it is tighter — management, user entities and user auditors. A SOC 3 carries no such restriction, which is what makes it the general-use report.

So: you may not publish the report on a public download page, however good the conversion math looks. You may describe it publicly — type, period, categories, firm, opinion — and that description is not restricted. And prospects are commonly treated as parties who can receive it once they have sufficient understanding, in practice under NDA, which is why a fast NDA path matters more to enterprise sales than any badge.

“Send us your SOC 2 certificate” almost always means “start the NDA so we can read your SOC 2 report”. Answer the second request.

From the other side

How to verify a vendor who says certified

If you are the buyer, the word tells you nothing on its own — plenty of well-run vendors use it carelessly, and plenty of thin programs use it confidently. Eight requests separate the two, and none of them requires you to read all 120 pages. Send them in one email.

The report cover page and the first page of Section 1

The name of the CPA firm, the report date, and that a signed opinion exists at all.

A one-page PDF carrying a seal, a reference number and an expiry date. No such instrument exists in the SOC framework.

The opinion paragraph itself, read in full

Whether the opinion is unmodified, or qualified, adverse or disclaimed — and what the modification was about.

The vendor cannot tell you which of the four it is, or answers “we passed”.

The period dates named in the opinion

That this is a Type 2, and exactly which months of operating effectiveness are covered.

Only an “issued”, “achieved” or “completed” date with no period. That usually means a Type 1.

Section 3 — the system boundary

That the specific product, environment and region you are buying sit inside the system that was examined.

“The whole company”, or a boundary that names a different product line or a legacy platform.

The trust services categories in scope

Security, plus availability, confidentiality, processing integrity or privacy wherever the vendor claims them.

Categories claimed in marketing or in the questionnaire that the opinion paragraph does not name.

Section 4 exceptions and management’s responses

What actually failed during the period, how often, and what was done about it.

“There were no exceptions”, asserted verbally, with no page reference you can check.

The CPA firm’s state license, and its independence on this engagement

That the signer is a licensed CPA firm and did not also design and implement the controls it tested.

The same firm ran the readiness project and then attested to its own work.

A bridge letter where the period ended more than about 90 days ago

Management’s written representation on what has changed between the period end and today.

No bridge letter, and no date for the next observation period end.

A vendor who answers all eight in one email is further along than one with a badge. If you are on the selling side of this table, the same list is your pre-flight check — every answer above should already be written down somewhere your account executives can reach it.

What sits behind the word

The evidence a CPA firm actually requests

“Attested” is the stronger word once you know what it is made of. Engagement acceptance is conditioned on management agreeing to provide a written assertion and, as the attestation standards require, written representations from the responsible party — both signed and dated as of the report date, at the end of the engagement. Early in the engagement the firm evaluates the system description against DC section 200, then defines populations and selects from them. The AICPA’s Audit Sampling Guide publishes tables that most firms work from, but no sample size is mandated for a SOC engagement, so two firms can test the same control differently and both be right.

Market practice

The selection counts in the fourth column are common firm methodology under the AICPA’s audit sampling guidance, not a published AICPA requirement. Your CPA firm sets them by assessed risk, and a higher-risk control attracts a larger selection at the same frequency.

Annual

Risk assessment (CC3.1–CC3.4), policy approval, DR test (A1.3), vendor reviews (CC9.2)

One occurrence — no sampling

1 — the whole population, inspected in full

The approved document, with approver and date inside the period; DR test plan, results, follow-up

An undated policy; a risk assessment approved after the period closed and dated back into it

Quarterly

User access reviews (CC6.3), privileged access recertification

Every in-scope system, every quarter, reconciled

All 4 occurrences; 2 of 4 where the control is assessed low-risk

The list actually reviewed, dated reviewer sign-off, proof the identified removals were completed

Sign-off with no evidence revocations happened; a filtered list that is not the full user population

Monthly / weekly

Vulnerability scanning and patching (CC7.1), backup monitoring (A1.2)

The full schedule of runs, exported from the tool

2–5 of 12 monthly runs; 5–8 of roughly 52 weekly runs

Scan reports showing date, target count and findings; remediation tickets closing each finding within SLA

One scan run on the last day of the period; remediation with no link to the finding it closes

Daily / continuous

Backup jobs, monitoring and alerting (CC7.2), logical access enforcement (CC6.1)

Job or alert history for the whole period, plus configuration state

10–25 selections from the period’s job or alert history, plus 100% inspection of the configuration

System-generated logs including failures and reruns; alert records with timestamps and disposition

A dashboard screenshot with no date range or scope; sampled successes with nothing proving the population

Many times daily

Change and release management (CC8.1)

Every change released, exported from the pipeline and reconciled to ticketing

25–40 changes drawn from a reconciled release population

Per selection: ticket, test evidence, approval recorded before release, approver ≠ requester

An export that does not reconcile to release history; approvals timestamped after deployment

Event-driven

Onboarding and termination (CC6.2, CC6.3), incident handling (CC7.3–CC7.5)

Joiners and leavers reconciled to the HR system of record

100% where the population is under about ten joiners, leavers or incidents; 10–25 above that

Grant and revocation timestamps against start or exit dates; incident tickets through to closure

A leaver list that does not match HR records — completeness fails before any sample is drawn

The general shape is that populations under about ten are tested in full and populations above roughly 250 rarely produce selections above 40 — the firm’s risk assessment, not the population size alone, drives the count. One consequence surprises people: a Type 1 has no operating-effectiveness testing at all, so no population is sampled anywhere in the engagement. The firm inspects design as of a single date. That is a further reason a Type 1 is nobody’s certificate — it says the controls were suitably designed on one day, and says nothing about whether they ran on any other.

Two rejection patterns cause most re-work, and neither is the control failing. The first is completeness: where a population comes from a report you produced yourself, the firm asks how you know it is complete and accurate — the query, the parameters, the date range, the reconciliation to a source system. The second is timing: evidence assembled after the period closed does not show the control operated throughout it. Certification builds its assurance differently — Stage 1, Stage 2, nonconformities graded major or minor, corrective action, then an independent certification decision by people who did not audit. Both routes are rigorous; only one ends in a certificate, because here the outcome is the testing.

Where this gets contested

The edge cases that generate the arguments

The rule is simple. Applying it to a live procurement portal, a signed contract, or a badge someone already shipped is where the questions start.

The buyer’s own form says “certified”

Their questionnaire is not a standards document. Answer in their field with the closest accurate value and add one clarifying line. Reviewers rarely object to the correction; they do object to a certificate number that turns out not to exist.

Two clocks that look like one

The AICPA logo terms run twelve months from the report date. Buyer freshness runs twelve months from the period end. For a period ending 30 June 2026 and a report dated 12 August 2026, they sit six weeks apart.

A “certificate of completion” from a firm or platform

Some audit firms issue a one-page confirmation; some compliance platforms produce a badge. Neither is a SOC 2 certificate, because no such instrument exists. They are marketing artifacts carrying no assurance — a serious reviewer still wants the report.

A tender that genuinely requires accredited certification

Some public-sector and regulated procurements are written around certification: certificate number, accredited issuer, expiry date. No careful SOC wording satisfies that. It is a framework problem rather than a wording problem, and the answer is usually ISO/IEC 27001 alongside SOC 2. The three markets below behave differently enough to be worth separating.

One report, several entities or products

The report covers the system described in Section 3 and the entity that signed the assertion. A group-wide claim when one subsidiary was examined is the same error as “certified”, and easier to catch. State the entity and the system, not the brand.

Marketplace listings with a fixed “Certifications” field

Cloud marketplaces often offer one dropdown labeled Certifications with SOC 2 in it. Select it — the taxonomy is theirs — and use the free-text field for type, period and NDA path. The label is not a claim you authored; the description is.

Your advisor cannot also be your auditor

The firm that designs and implements your controls cannot then attest to them; independence rules do not permit it. Tranquility Cybersecurity performs readiness, implementation, evidence and audit coordination alongside the licensed CPA firm. TCSA never certifies, attests or signs.

The tender case deserves unpacking, because the word “certification” is genuinely load-bearing outside US enterprise procurement and the right response changes by market.

United States — enterprise procurement

SOC 2 is the native instrument. Buyers ask for the report, security exhibits are drafted around it, and reviewers know what Section 4 is. “Certified” is the only error that needs fixing; nothing else needs translating.

United Kingdom & EU — public tenders

Tenders are frequently written around an accredited certificate: certificate number, accredited issuer, expiry date, accreditation mark. No careful SOC wording satisfies that, because the evaluator is checking for an instrument SOC does not produce. ISO/IEC 27001 is the answer, and the SOC 2 report rides alongside as control detail.

UAE & India — regulated procurement

The buyer’s own framework usually names certification and the evaluation sheet follows it. A SOC 2 report is commonly accepted as supplementary control evidence rather than as the named instrument — offer it in those terms, and hold the certificate separately rather than arguing the form is wrong.

Objection handling

The nine pushbacks you will get

Each answer ends in something someone can do this week, because a stance nobody executes changes nothing on the trust page.

“Our competitors all say SOC 2 certified. Why be the only precise one?”

Because precision is free and the downside is asymmetric: the accurate sentence names the type, the period and the firm — exactly what the reviewer was about to ask for. Do this: replace the claim on the trust page with one line carrying type, period, CPA firm and NDA path, then paste the identical line into the RFP answer library so nobody re-emits the old one next week.

“Isn’t this pedantry? Everyone knows what we mean.”

The reviewer knows what you mean. What they infer is whether you have read your own report — anyone who has read Section 1 knows it contains an opinion, not a grant of status. Do this: have whoever owns the trust page read the opinion paragraph of your own report once, out loud. The wording corrects itself in ten minutes and stays corrected.

“Our procurement portal will not accept anything but a date.”

Give it a real date and label it. Do this: enter the period end; if the field validates and rejects a past date, enter the next period end instead. Then use the first free-text field — comments, scope, or the covering email — to record that SOC 2 produces a report, that no expiry applies, which date you entered and why.

“Marketing says the long version kills conversion on the trust page.”

Split it. The badge row carries the AICPA SOC logo under its registration terms; the line underneath does the accuracy work — type, period, CPA firm, report under NDA. Do this: badge above, one sentence below, NDA request link beside it, and measure the NDA click rather than the badge impression.

“Our auditor’s own website says certification.”

Some firms use it in marketing copy, and it is worth raising. The governing text is the report: no opinion issued under AT-C 205 calls itself a certification, because the standard gives the practitioner no authority to certify. Do this: quote your own opinion paragraph back to them and ask that engagement correspondence use the report’s own vocabulary.

“Our website already says certified in 40 places and it is indexed.”

Fix it in the order of consequence, not the order of visibility. Signed security exhibits first, because those create obligations. Then the trust page and pricing page. Then marketplace listings, G2 and LinkedIn profiles. Then the RFP answer library and sales decks — move that one earlier if your team is actively responding to questionnaires, because the library is the source that keeps re-emitting the phrase. Indexed blog posts last: they are the most visible and the least load-bearing.

“Legal says changing the wording now looks like admitting misrepresentation.”

The correction is additive, not a withdrawal. You are adding the type, the period, the CPA firm and the opinion to a claim you already made — not retracting the claim that an examination happened. Do this: land the change at the next report issuance so the edit has an event attached to it, and record the issuance date beside the change so the timeline reads as maintenance rather than retraction.

“Our compliance platform gave us a SOC 2 badge. Can we keep it?”

That badge is the platform’s artwork. It is not the AICPA mark, it carries no opinion, no type, no period and no scope, and it is not evidence of anything a reviewer can test. The AICPA SOC logo is a separate thing: it requires your own registration, against a report issued to you, and only where that report does not contain a modified opinion. Do this: register for the AICPA mark if you want a badge at all, and put the accurate sentence underneath it either way.

“Our customer’s regulator requires certification.”

That is a framework problem, not a wording problem. No careful SOC sentence satisfies a requirement written around an accredited certificate with a number and an expiry date, because the evaluator is checking for an instrument the SOC framework does not produce. Do this: name ISO/IEC 27001 as the instrument that answers it — the two are commonly held together — and keep the SOC 2 report as the control-level evidence a certificate does not carry.

Lift and use

Copy these four blocks

Everything above becomes a wording argument unless someone can paste the fix. Dates, entity and firm names below are placeholders — substitute your own period, your own entity and your own CPA firm before publishing.

Trust page line

SOC 2 Type 2 examination completed for 1 January – 30 June 2026, reported on by [CPA firm], an independent licensed CPA firm. Unmodified opinion. Report available under NDA.

Security questionnaire — “certification held” field

SOC 2 Type 2 — attestation report under AICPA standards, issued by an independent licensed CPA firm; not a certification. No certificate number exists. Report available under NDA.

RFP narrative paragraph

[Entity] completed a SOC 2 Type 2 examination covering the period 1 January – 30 June 2026, addressing the trust services criteria for security, availability and confidentiality. The examination was performed by [CPA firm], an independent licensed CPA firm, which issued an unmodified opinion; the report is dated 12 August 2026. The report is restricted-use and is provided under NDA, normally within two business days of execution. The next observation period ends 30 June 2027, and periods are consecutive with no uncovered gap.

Contract clause replacement

Delete

Supplier shall maintain SOC 2 certification throughout the term.

Replace with

Supplier shall maintain a current SOC 2 Type 2 report covering the trust services criteria for security, availability and confidentiality and the system used to provide the Services, issued by an independent licensed CPA firm, with consecutive observation periods leaving no uncovered gap, and shall provide each such report to Customer under NDA within thirty (30) days of issuance, together with a bridge letter on request where more than ninety (90) days have elapsed since the end of the most recent observation period.

Frequently Asked Questions

Is there such a thing as a SOC 2 certificate?

No. A SOC 2 engagement is an attestation examination performed by an independent licensed CPA firm under AT-C sections 105 and 205, producing a report that contains an opinion. There is no certification body, no accreditation scheme behind one, no certificate number, and no register of report holders anyone can search. Where you see a "SOC 2 certificate", someone has designed a document with no standing in the AICPA framework. The instrument carrying the assurance is the report, and specifically the opinion in its first section.

Can we say we are "SOC 2 certified" on our website?

It is factually wrong, and an experienced reviewer reads it as evidence that whoever wrote the page has not read the report. Write what you hold: "SOC 2 Type 2 examination completed for 1 January – 30 June 2026, reported on by an independent licensed CPA firm; report available under NDA." That is one line longer and answers the reviewer's first four questions — type, period, who performed it, how to obtain it. If you want a visual mark, the AICPA SOC logo is the legitimate option under its registration terms.

What is the difference between certification and attestation?

Certification is a conformity-assessment activity: an independent certification body audits your organization against a standard and issues a certificate, and that body is normally accredited under ISO/IEC 17021-1. Attestation is a professional service: a licensed CPA firm examines a subject matter and reports an opinion under the AICPA attestation standards. One produces a status with an expiry date; the other produces a professional opinion covering a stated period. ISO/IEC 27001 is the first; SOC 2 is the second.

Is "SOC 2 compliant" acceptable instead?

It is less wrong, and common enough that few reviewers challenge it, but it remains imprecise. There is no SOC 2 rulebook to comply with — the trust services criteria are outcome-based, and each organization designs its own controls to meet them, which is why two reports in the same industry can look quite different. The accurate framing names the examination rather than a compliance state: "our controls were examined against the trust services criteria for security, availability and confidentiality, with an unmodified opinion."

Who may display the AICPA SOC logo, and for how long?

The SOC for Service Organizations logo is available to an organization that has had a SOC 1, SOC 2 or SOC 3 report that does not contain a modified opinion issued by a licensed CPA, after registering with the AICPA and accepting its terms. That eligibility bar bites: a qualified, adverse or disclaimed opinion removes logo eligibility even though the examination was completed. Use is permitted for twelve months following the report date; if no new report is issued by then, use must stop. The artwork may not be altered except in size and must link to the AICPA’s SOC page. A separate logo exists for the CPA firms performing the examinations — a service organization may not use that one.

How do I answer a form that only has a "certification expiry date" field?

Give it a real date rather than leaving it blank or inventing one. Enter the end of the observation period as the reference date, and add in the nearest free-text field or the covering email that SOC 2 produces a report rather than a certificate, that no expiry applies, and when the next period ends. If the portal validates the field and rejects a past date — some auto-flag the vendor as lapsed before a human reads the note — enter the next period end instead and say so in the same note. Never enter a date derived from the report date, which implies an expiry that does not exist. For a certificate-number field, write "not applicable — SOC 2 produces a report; available under NDA".

Can we publish our SOC 2 report on our website?

No. A SOC 2 report is restricted-use: the attestation standards require an alert identifying the parties it is intended for, which for a SOC 2 means user entities, their auditors, and others with sufficient understanding of the service organization and its system. Publishing it distributes a restricted-use document beyond that group. What you can publish is a description of the engagement and, if you want a public artifact, a SOC 3 report — produced from the same examination for general use, carrying the opinion, management’s assertion and a high-level system description, but not the full DC 200 description or the description of the auditor’s tests and results.

Our contract says we must "maintain SOC 2 certification". What now?

Redline it before signature, because as written it is an obligation you cannot literally satisfy and it will be quoted back at renewal or during an incident. Replace it with something you can meet and evidence: maintain a current SOC 2 Type 2 report covering the named trust services categories and the system used to provide the services, issued by an independent licensed CPA firm, with consecutive observation periods leaving no uncovered gap, provided under NDA within a stated number of days of issue, with a bridge letter on request. The full clause text is in the "Copy these" section above.

How do I verify a vendor who tells me they are SOC 2 certified?

Ignore the word and ask for eight things in one email: the report cover page, the opinion paragraph, the period dates, the Section 3 system boundary, the trust services categories in scope, the Section 4 exceptions and management responses, confirmation of the CPA firm’s license and independence, and a bridge letter if the period ended more than about ninety days ago. The answers tell you whether you are looking at a Type 1 or a Type 2, whether the product you are buying was in scope, and whether the opinion was modified. A vendor who answers all eight in one email is further along than one with a badge.

Does ISO 27001 have the same vocabulary problem?

The opposite one. ISO/IEC 27001 certification is real, so the errors run the other way: claiming "ISO certified" without naming the certification body, holding a certificate from a body with no recognized accreditation, or displaying the ISO logo — which ISO does not license for that purpose, because ISO certifies nobody. The correct claim names the standard and version, the scope statement, the certification body, the certificate number and the validity dates, and displays the certification body’s mark.

Related reading: what a SOC 2 attestation is, who can perform a SOC 2 audit, how long a SOC 2 report is valid, how to read a SOC 2 report, the types of SOC reports, SOC 2 in enterprise sales, and the SOC 2 hub.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: August 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations