# SOC 2 Audit | Secureframe

canonical: https://secureframe.com/hub/soc-2/audit

Completing an AICPA SOC 2 audit can give your customers a new level of trust and respect for your business – but going through an information security audit is no small feat. Knowing what to expect at each stage of the audit process can help you better prepare and reduce the level of stress involved. 

What happens during a SOC 2 audit? How long does an audit take? What are the typical costs? 

This section will provide clarity around how a SOC 2 audit is completed so that when you go through one, you’ll know exactly what to expect.

## Intermediate: I’m Preparing for an Audit

**So you’re getting ready for your first SOC 2 audit. **

Completing a SOC 2 audit is a major undertaking that involves collaboration from all parts of your organization, from your executive team to your newest hire. Knowing what to expect can help you prepare for a smooth audit, making it easier to manage the project and set expectations internally. 

![](https://prismic-io.s3.amazonaws.com/secureframe-com/96d08012-d1b6-4a0e-bc92-1ab756a54835_2.+Hub+Content_+SOC+2+Middle+01%402x.png)

## What Happens During a SOC 2 Audit?

The SOC 2 auditor will spend anywhere from a few weeks to a few months working with your team before producing a final SOC 2 report. They’ll likely start with a security questionnaire, asking your team about company policies, procedures, infrastructure, and controls. 

Next, auditors will review evidence and documentation that proves your systems and controls are designed and functioning in a way that aligns with SOC 2 requirements. 

Examples of requested evidence are: 

- Asset inventories
- Risk and change management policies
- Equipment maintenance records
- System backup logs
- Code of conduct and ethics policies
- Business continuity and incident response plans

Your auditor will likely have follow-up questions and need to ask your team for clarification on processes or controls, or they may request additional documentation as evidence. Depending on which type of report you choose, the auditor will also interview management, observe processes in place, and inspect evidence to meet SOC 2 requirements. 

At the end of the audit, you’ll get a written SOC 2 report outlining the results and stating the auditor’s opinion. Here are the possible outcomes:

- **Unqualified**: All evidence was accepted as fully meeting the SOC 2 requirements.
- **Qualified**: A few controls were found to not meet the SOC 2 requirements based on evidence reviewed.
- **Adverse**: Multiple or critical controls were found not to meet the SOC 2 requirements. Disclaimer of Opinion: The auditor doesn’t have enough information to draw a fair conclusion.

## Scoping a SOC 2 Audit 

Before an auditor ever steps foot in your office, you’ll need to determine what type of SOC 2 report you need and which Trust Services Criteria you’ll include. 

- A SOC 2 Type I report analyzes whether your systems are designed according to your selected Trust Services Criteria. Type I audits are typically less expensive and time-consuming than Type II. But they provide less complete information and assurance for customers. 
- A SOC 2 Type II report examines how your systems are designed AND how processes are followed over a period of time. This type of report takes longer (3-12 months). 

Choose your audit type with your goals, budget, and timeline constraints in mind. 

Next, select your Trust Services Criteria. Remember, you don’t need to become compliant with all five if you don’t want to — only Security is required to complete an audit. 

![](https://images.prismic.io/secureframe-com/bdda47cb-6624-40e1-801f-65f1ce2524fa_9.+Hub+Content_+Audit+Scope+01%402x.png?auto=compress,format)

## Conducting Gap Analysis and Readiness Assessments

A gap analysis compares where your internal controls stand today and where they need to be to comply with SOC 2. This comparison helps you identify any missing pieces (gaps) and fix them before beginning your audit. 

As part of audit prep, many companies choose to complete a readiness assessment. During this assessment, an auditor explains the requirements of the Trust Services Criteria you’ve selected for your audit, performs a gap analysis,  then provides a prioritized list of recommendations. 

A readiness assessment might seem like an extra, unnecessary step, but think of it as a test run for your audit.

It will help you remediate any gaps that would cause an auditor to deliver an adverse opinion and potentially save you from having to complete another audit. 

## Choosing an Auditor

Only an accredited CPA can perform a SOC 2 audit and issue your company a formal report. So find a firm that’s AICPA-affiliated and conducts audits based on the latest guidelines. It’s also important to look for an auditor who has experience with your company size and industry. 

![](https://images.prismic.io/secureframe-com/32016832-8b3e-4b17-b05b-1460a08b9bc8_Hub+Content_+The+Audit+Process+02%402x.png?auto=compress,format)

Preparing for a successful audit can be a months-long endeavor, so it's important to understand the steps involved before you begin. 

This section explains the audit process in-depth, including average costs and timelines for Type I and Type II reports.
