American buyers ask for SOC 2 the way British ones ask for ISO 27001, and the two are not interchangeable. SOC 2 is an attestation report written by an accountancy firm against criteria from the AICPA, describing how your controls operated over a period. For a UK software business, the first serious enterprise deal in the United States is usually where the question arrives.

Type I and Type II are different products
A Type I report describes your controls at a point in time and says they were suitably designed. A Type II covers a period, typically three to twelve months, and says they operated effectively throughout it. Buyers who know the difference want Type II, so a Type I is best treated as a stepping stone rather than a destination. That distinction drives the timeline: you cannot compress an observation window, which means a customer asking for a Type II in six weeks is asking for something that does not exist yet.
Where testing evidence fits
Security is the only mandatory trust services category and it is where testing lands. The criteria covering vulnerability identification and monitoring expect you to detect and respond to weaknesses, and an annual penetration test with documented remediation is the usual evidence. Auditors look for consistency over the window rather than a single good report, so a test at the start of the period with findings still open at the end is worse than no test in evidential terms. Web application security assessments carry most of the weight for a SaaS platform, since that is where customer data is handled.
“The mistake I see repeatedly is treating the audit as the project. The report describes what you actually did for six months, so if your patching slipped in March, that is in the report. Fix the operating rhythm first and let the observation window run over a period you would be happy to have examined.”
William Fieldhouse, Director, Aardwolf Security Ltd
How it compares with ISO 27001
ISO 27001 certifies a management system against a standard, and SOC 2 attests to how specific controls operated. The underlying work overlaps heavily, so a firm with a functioning management system will find much of the evidence already exists. Where they differ is audience and output: ISO gives you a certificate that a European buyer recognises, and SOC 2 gives an American buyer a detailed report their own auditors can read. Firms selling on both sides of the Atlantic often end up with both, and mapping the controls once saves duplicating the evidence gathering.
Data protection still applies
A SOC 2 report says nothing about your obligations under UK GDPR, and the Information Commissioner’s Office expectations around security of processing and international transfers remain regardless of what an American auditor concludes. If you are moving personal data to United States infrastructure to serve those customers, treat the transfer mechanism as a separate piece of work. When you select a penetration testing company with SaaS experience, ask whether their reports have been used in SOC 2 audits before, because a report structured with that audience in mind saves a great deal of explanation.
Frequently asked questions about SOC 2
These questions come up when the first American enterprise contract appears.
How long does the first SOC 2 take?
Realistically six to nine months from a standing start, most of which is the observation window plus the remediation you do before it opens. Firms with ISO 27001 already in place move faster because the evidence habits exist.
Do you need a penetration test for SOC 2?
It is not explicitly mandated and it is what most auditors expect to see. Independent testing is the simplest evidence that vulnerabilities are identified and addressed, and its absence usually leads to a longer conversation.
