How soc 2 works
A SOC 2 Type I report evaluates whether a company's controls are designed appropriately at a single point in time, while a Type II report tests whether those controls actually operated effectively over a period, typically six to twelve months. Type II is generally seen as the stronger, more credible report of the two.
Getting a SOC 2 report involves choosing which trust service categories to include, building and documenting the required controls, and engaging an independent CPA firm to perform the audit, a process that commonly takes many months. Not every vendor holds one, and businesses evaluating a service provider should ask directly rather than assume. Businesses that need a SOC 2 report for a specific customer, rather than as an ongoing practice, sometimes start with a narrower scope covering only the systems that customer cares about, then expand the scope in later audit cycles as more customers request one.
Example
A software company handling customer payment data undergoes a SOC 2 Type II audit covering the security and confidentiality categories over a six-month period. The auditor tests controls such as access reviews, encryption and incident response, then issues a report that the company shares with enterprise customers during their vendor security review process. The company shares the finished report only under a non-disclosure agreement, since SOC 2 reports contain sensitive detail about internal controls that vendors generally do not publish openly.
SOC 2 in QuickBooks Online vs Xero
Not software-specific: SOC 2 is an audit outcome rather than a QuickBooks Online or Xero feature, though both platforms' own SOC reports are publicly referenced by Intuit and Xero as part of their vendor security documentation. A business preparing for its own SOC 2 audit typically uses a compliance platform to track evidence across its tools.
Related terms
How LedgerBPO handles soc 2
LedgerBPO lists certifications only when they are actually held, and we state our current security certification status plainly on our security page rather than implying one we do not hold. We apply strong operational controls, including MFA and access restrictions, regardless of certification status.