SOC 2 Type II

SOC 2 Type II

SOC 2 Type II is an auditing standard that verifies a company's security controls work reliably over an extended period, typically six to twelve months, not just at a single point in time. An independent CPA firm examines evidence from that window and reports on specific criteria, such as security, availability, or confidentiality.

Buyers evaluating an AI vendor for customer data can't just take a sales deck's word for it. SOC 2 Type II turns that trust question into an auditable one: a licensed CPA firm reviews how a company's controls actually performed, not how they're described in a policy document.

What is SOC 2 Type II?

SOC 2 Type II is an attestation report, defined by the AICPA (American Institute of CPAs), that evaluates a service organization's controls against one or more Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Most companies scope their report to a subset of these; Fin's own SOC 2 Type II report, for example, covers security, availability, and confidentiality.

The "Type II" distinction matters. A Type I report checks whether controls are designed correctly as of one date. A Type II report checks whether those same controls operated effectively across a defined observation period, usually six to twelve months. Type II is the stronger signal because it proves the controls held up under real operating conditions, not just on paper.

Why SOC 2 Type II Matters

For a company handling customer conversations and account data through an AI agent, SOC 2 Type II is often the first document a security or procurement team asks for. It shortens vendor due diligence by replacing a long list of security questionnaire items with a single, independently verified report.

  • Continuous verification: controls are tested over months, not audited once and forgotten
  • Independent assurance: the report is produced by a licensed CPA firm, not the vendor itself
  • Renewal cadence: reports are typically reissued annually, so the audit period never goes stale for long

How SOC 2 Type II Works

  1. The company defines which Trust Services Criteria apply to its services
  2. It documents and implements controls addressing those criteria (access management, monitoring, incident response, and so on)
  3. An independent auditor observes evidence of those controls operating over the reporting period
  4. The auditor issues the report, scoped to the criteria tested
  5. Between full report cycles, companies often issue bridge letters confirming controls remain in effect

Most vendors, including Intercom, make their SOC 2 Type II report available through a trust center rather than posting it publicly, since the report contains sensitive security detail. Requesting a copy usually requires a signed NDA if you're not yet a customer.

SOC 2 Type II vs ISO 27001

SOC 2 Type IIISO 27001
Type of documentAttestation reportCertification
Issued byLicensed CPA firmAccredited certification body
ScopeChosen Trust Services CriteriaFull Information Security Management System
GeographyUS-originated, globally usedInternational standard
Public visibilityUsually shared under NDACertificate itself is often shareable

The two aren't interchangeable. SOC 2 Type II proves controls performed over time; ISO 27001 proves a company runs a structured, continuously improving security management program. Many enterprise vendors hold both.

Frequently Asked Questions

Does SOC 2 Type II mean a company covers all five Trust Services Criteria?

Not necessarily. Companies choose which criteria apply to their services. Always check the report's scope section rather than assuming full coverage from a badge alone.

How is SOC 2 Type II different from SOC 2 Type I?

Type I confirms controls are designed correctly on a single date. Type II confirms those controls actually operated effectively across a multi-month period, which is why most enterprise buyers ask for Type II specifically.

Related Terms

The #1 AI Agent for all your customer service