INDUSTRY / AICPA

SOC 2

System and Organization Controls 2 · AICPA Trust Services Criteria (TSC 2017, with Point-in-Time revisions) · 5 categories · 64 criteria · CPAs issue reports

SOC 2 is an auditing framework for service organizations, developed and maintained by the American Institute of Certified Public Accountants (AICPA). It evaluates how well an organization manages customer data based on the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Unlike PCI DSS or HIPAA, SOC 2 is not a law or regulatory mandate — it is a market-driven compliance standard that has become essential for B2B technology companies, particularly SaaS and cloud providers.

Cloud AI providers need SOC 2 for enterprise sales. It is the baseline trust requirement — without a SOC 2 report, most enterprise procurement processes will not advance. This creates a barrier to entry: small AI startups cannot sell to enterprise customers without investing in SOC 2 audits, which cost $20,000–$80,000+ annually and require months of preparation. The result is a market structure where established cloud providers with existing SOC 2 programs have a durable advantage over new entrants.

Trust Services Criteria TSC

Security (Common Criteria): The mandatory baseline. Covers protection of system resources against unauthorized access — logical and physical access controls, system operations, change management, and risk mitigation. All SOC 2 reports include the Security criteria. The Common Criteria contain 9 control categories (CC1–CC9) with approximately 30 criteria.

Availability: The system is accessible and usable as committed or agreed. Covers performance monitoring, environmental protections, backup and recovery, and incident response. Relevant for AI services that must meet uptime SLAs.

Processing Integrity: System processing is complete, valid, accurate, timely, and authorized. For AI systems, this means model outputs are reliable and data pipelines process inputs correctly. Particularly relevant for AI used in financial processing, healthcare diagnostics, or automated decision-making.

Confidentiality: Information designated as confidential is protected as committed or agreed. Covers encryption, access controls, and data classification. AI training data, model weights, and customer data processed through AI systems are typically classified as confidential.

Privacy: Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and applicable privacy regulations. Aligns with GDPR, CCPA, and other privacy laws. AI systems that process personal data must demonstrate privacy controls throughout the data lifecycle.

AI IMPACT

Security and Confidentiality are the baseline AI requirements. Every cloud AI provider needs at minimum a SOC 2 Type II report covering the Security (Common Criteria) and Confidentiality categories. Enterprise customers will not sign contracts without it. The Common Criteria's 9 control categories map directly to how AI providers secure their infrastructure, manage access to model APIs, and protect customer data used for inference or fine-tuning.

Processing Integrity is the AI quality challenge. For AI providers offering models for automated decision-making (fraud detection, content moderation, healthcare triage), Processing Integrity requires demonstrating that outputs are accurate and reliable. AI models are inherently probabilistic — proving "processing integrity" for a system that sometimes hallucinates is a novel audit challenge that the AICPA has not issued specific guidance for.

Source: AICPA SOC 2 Overview · AICPA Trust Services Criteria 2017 · AICPA & CIMA
Type I vs Type II Reports Type I/II

SOC 2 Type I: Evaluates the suitability of design of controls at a point in time. The auditor confirms that the organization's controls are designed appropriately to meet the Trust Services Criteria as of a specific date. Type I reports are faster and cheaper to obtain but less valuable — they prove you designed good controls, not that they operate effectively.

SOC 2 Type II: Evaluates the operating effectiveness of controls over a period of time (typically 3–12 months, most commonly 12). The auditor tests whether controls actually functioned as designed throughout the observation period. Enterprise customers almost universally require Type II — a Type I report is rarely sufficient for major procurement contracts.

The Type II observation period creates a chicken-and-egg problem for new AI companies: they need SOC 2 Type II to win enterprise customers, but they need enterprise customers to justify the cost of a 12-month audit. Many AI startups begin with Type I and upgrade to Type II as their customer base grows.

AI IMPACT

The Type II requirement creates a time-based barrier to entry. A new AI company can't produce a Type II report without first running controls for 12 months. Enterprise customers won't buy without a Type II report. This means new AI providers face a 12-month minimum delay before they can compete for enterprise contracts — during which established providers with existing Type II reports capture the market.

The cost structure favors well-funded AI companies. SOC 2 Type II audits cost $30,000–$80,000+ annually for mid-size companies, plus the internal cost of maintaining compliance documentation and controls. For a bootstrapped AI startup, this is a significant revenue drag. For a venture-backed company, it's a budget line item. The compliance cost differential advantages funded companies over independent developers.

Source: AICPA SOC 2 · AICPA SOC 2 Guide
SOC 2 as Enterprise Sales Gatekeeper Procurement

SOC 2 has become the de facto admission ticket for B2B technology sales. Enterprise procurement teams include SOC 2 Type II report requests in vendor security questionnaires, RFP requirements, and contract terms. The report is rarely read in full — its existence is what matters. A vendor without a SOC 2 report is filtered out before evaluation; a vendor with a SOC 2 report passes the initial gate.

This dynamic has created a compliance industry: SOC 2 readiness platforms (Vanta, Drata, Secureframe, Tugboat Logic) automate control monitoring and evidence collection, reducing the cost of maintaining SOC 2 compliance. These platforms typically cost $5,000–$20,000/year and integrate with cloud infrastructure, HR systems, and code repositories to continuously verify control operation.

The AICPA has noted concerns about SOC 2 audit quality, including allegations about compliance vendors offering SOC 2 services with inadequate audit procedures. In response, the AICPA has emphasized that SOC engagements must be performed by licensed CPA firms following professional standards, and has referred unlicensed practitioners to state regulators.

AI IMPACT — CRITICAL

SOC 2 is the enterprise AI market gatekeeper. Cloud AI providers — from OpenAI and Anthropic to smaller inference providers — need SOC 2 Type II to sell to enterprise customers. Without it, procurement teams won't evaluate the product, regardless of technical merit. This means the enterprise AI market is structurally limited to companies that can afford and sustain SOC 2 compliance programs.

The compliance automation market is itself an AI market barrier. SOC 2 readiness platforms (Vanta, Drata, etc.) are the practical path to affordable SOC 2 compliance. But these platforms assume standard SaaS architecture — cloud infrastructure, centralized identity management, conventional application deployment. AI companies with non-standard architectures (distributed training, custom GPU clusters, novel inference pipelines) may find that compliance automation tools don't map cleanly to their infrastructure, requiring manual evidence collection and increasing audit costs.

Self-hosted and open-source AI providers face the highest SOC 2 barrier. A company offering self-hosted AI software (rather than a managed cloud service) must help each customer achieve SOC 2 compliance for their deployment — or accept that enterprise customers will choose managed alternatives with existing reports. The compliance structure favors managed cloud AI over self-hosted AI, reinforcing centralization.

Cloud AI Provider Compliance AI SaaS

Major cloud AI providers publish SOC 2 reports covering their AI services. AWS, Azure, Google Cloud, OpenAI, Anthropic, and others maintain SOC 2 Type II reports that customers can request under NDA. These reports cover the infrastructure layer (compute, storage, networking) and the AI service layer (model APIs, training pipelines, data processing).

For customers using these providers, SOC 2 reports serve as inherited controls — similar to FedRAMP inheritance in the government space. The customer's own SOC 2 scope is reduced to the controls they manage: access management, data classification, and application-level controls. The cloud provider's SOC 2 covers the infrastructure security.

This inheritance model means that enterprise customers using cloud AI providers get SOC 2 coverage "for free" at the infrastructure level — while customers running self-hosted AI must achieve SOC 2 compliance for their entire stack. The economic incentive aligns with cloud AI adoption, not self-hosted deployment.

AI IMPACT

SOC 2 inheritance creates the same structural bias as FedRAMP inheritance in CMMC. Cloud AI providers with SOC 2 reports offer customers a reduced compliance scope. Self-hosted AI requires the customer to own the full scope. For any organization subject to SOC 2 procurement requirements, cloud AI is the lower-compliance-cost path — reinforcing the centralization pattern we see across every framework.

Large AI providers' SOC 2 reports are competitive moats. OpenAI, Anthropic, and other frontier model providers invest significant resources in maintaining SOC 2 Type II reports. These reports are not just compliance artifacts — they are market barriers. A new model provider with superior technology but no SOC 2 report cannot compete for enterprise contracts. The compliance investment becomes a durable competitive advantage independent of model quality.

Source: AICPA SOC 2 · Provider compliance pages (AWS, Azure, GCP, OpenAI, Anthropic)

Related frameworks: ISO/IEC 27001 (international ISMS standard often obtained alongside SOC 2) · PCI DSS v4.0 (payment data — service providers often need both) · FedRAMP (federal equivalent of the enterprise SOC 2 gate) · HIPAA Security Rule (healthcare AI providers need SOC 2 + HIPAA) · ISO/IEC 42001 (emerging AI management system standard complementing SOC 2)

Investigation tracks: The Compliance Trap (SOC 2 as enterprise procurement gate) · The Infrastructure Play (SOC 2 inheritance favoring cloud AI) · The Asymmetry (established AI providers vs new entrants — compliance moat)