Which software helps with SOC 2 preparation?
Key takeaways
- Software prepares a SOC 2 examination; it does not issue the report. A SOC 2 examination ends with a SOC 2 report, Type I or Type II, not with a certificate.
- An audit firm signs the report. The AICPA describes SOC 2 examinations as work performed by "CPAs in public practice", which is a different authorization framework from the ISO/IEC 17021 accreditation that ISO 27001 certification bodies work under.
- The decisive selection criterion is not the feature list, it is the evidence history. A Type II report covers an observation period of typically three to twelve months; a snapshot of today's status does not satisfy it.
- Of the five Trust Services Criteria, only Security is mandatory. Availability, Processing Integrity, Confidentiality, and Privacy enter the scope only if you put them there.
- A company already running an ISO 27001 ISMS has covered much of the security work. What matters is whether the tool credits that work against the Common Criteria or asks for it a second time.
SOC 2 preparation software does three things: it connects your systems, collects evidence from them continuously, and maps that evidence to the controls under examination. That covers the part which consumes the most time when done by hand. Everything after that, the independent examination and the report, sits outside the software. For European companies two further criteria apply that most vendor roundups leave out: where the evidence is stored, and whether existing ISO 27001 work is credited.
What can software do for SOC 2 preparation, and what can it not do?
Almost all of the value sits in evidence management. A platform reads configurations from AWS, Azure, or Google Cloud, access logs from your identity management, and output from your security tooling, stamps each item with a date and an expiry, and attaches it to the relevant control. On top of that come policy management with versioning and approvals, and continuous monitoring that flags a drifting configuration instead of leaving it undetected until the next sample check.
Three things no software can do, whichever vendor you pick.
It does not issue the report. That is not a feature gap, it is how the procedure is built: the examination is performed by a party that had no hand in the implementation.
It does not replace the security work. A control that is documented in the tool but not lived in operations shows up in the examination, and automated evidence collection tends to make that more visible rather than less.
It does not shorten the observation period. A Type II report requires that the controls functioned over a period of time. That period is elapsed time, not a configuration setting. Software makes sure evidence exists for every day of it; it cannot skip the calendar.
Who issues the SOC 2 report?
SOC 2 is an examination performed under the standards of the AICPA, the US professional body for certified public accountants. The AICPA describes the audience for its own SOC 2 guide as "CPAs in public practice engaged to perform SOC 2 and SOC 3 examinations". The report carries that firm's opinion.
In practice this means you engage an audit firm able to sign under the AICPA standards. That is a different authorization framework from the one your ISO 27001 certification body works under, since certification bodies are accredited to ISO/IEC 17021. The two procedures run separately and are commissioned separately, even where the same controls sit underneath.
For you as a buyer that yields a quick test: a vendor advertising a "SOC 2 certification" or issuing its own SOC 2 seal is describing a procedure that does not exist.
Which criteria belong in your scope, and which observation period makes sense, is a question for your audit firm. This article is not a substitute for professional or legal advice.
What should you look for in SOC 2 preparation software?
The following eight criteria separate the offerings more sharply than any feature list. The third column is the actual test: it describes how you spot, in a demo, that a criterion is only being claimed.
| Criterion | Minimum requirement | How you spot a shortfall |
|---|---|---|
| Hosting and data location | Evidence, control gaps, and risk assessments sit on European infrastructure, and the location is contractually committed. | The vendor names an EU region but says nothing about its group structure or the law its parent company answers to. |
| Control mapping to ISO 27001 and GDPR | One stored measure counts simultaneously against Annex A, the Common Criteria, and Art. 32 GDPR. | The frameworks sit side by side as separate lists and you upload the same evidence more than once. |
| Evidence collection | Evidence is pulled automatically through integrations with cloud, identity management, and code repositories, and stored with a timestamp. | "Integration" in the proposal means only a connection that you then configure and populate by hand. |
| Type I and Type II | The tool maintains an unbroken evidence history across the whole observation period, not just the current state. | The dashboard shows today's status, but you cannot retrieve evidence for an arbitrary day six months ago. |
| Trust Services Criteria covered | Security as the mandatory criterion, plus the four optional criteria, each selectable on its own. | Only Security is modelled; Availability and Confidentiality, which enterprise buyers routinely ask for, are missing. |
| Access for the audit firm | The auditors get their own logged read access to evidence and controls. | You export evidence into a folder and handle every follow-up request by email. |
| Expert support | Scope, response time, and ownership of the expert support are written into the contract. | Support means a ticket system for product questions; questions about how to design a control are billed separately. |
| Who issues the report | No vendor. The SOC 2 report is signed by the audit firm you engage. | The vendor advertises a "SOC 2 certification" or issues a SOC 2 seal of its own. |
Which vendor models exist?
The offerings on the market reduce to four models. The difference between models is larger than the difference between two vendors within one model.
North American compliance automation. Built around SOC 2, and correspondingly mature on integrations and evidence collection. European requirements arrived later. Check the data location, the group structure, and the depth of the GDPR mapping specifically.
Classic GRC suites. Built for large organizations with their own compliance team. Highly configurable, and correspondingly heavy to set up and maintain. Evidence collection is often storage rather than automation.
General project and document tools. Spreadsheets, wikis, and task tracking with a compliance template on top. Workable for a first inventory, not for a Type II period, because the required evidence history with timestamps and expiry dates is missing.
European compliance platforms with expert support. Software and expert guidance from one provider, built for EU frameworks. Check whether the guidance is in the contract or arrives as a separate consulting engagement.
How does an existing ISO 27001 certification help with SOC 2?
It helps considerably, though not in the way it is usually described. Much of the security work in Annex A maps directly onto the Common Criteria; access control, encryption, incident management, change management, and supplier management all count in both frameworks. Which control lands where is set out in our comparison of ISO 27001, GDPR, and SOC 2 on one control set.
The difference is not in the controls, it is in the evidence required. For Annex A, a documented policy plus a sample is often enough. A Type II report requires evidence across the entire observation period. A company that built its evidence management for ISO alone discovers at its first SOC 2 report that the history is missing, and a missing period cannot be created after the fact.
For software selection that means a mapping in the product brochure is worth little if the tool holds evidence only as a current state. In the demo, ask for evidence covering a specific date in the past.
When is a SOC 2 platform the wrong answer?
There are cases where this category of software is not what you need.
If you sell only in Europe and nobody is asking for a SOC 2 report, you do not need SOC 2 preparation. The market standard in Europe is ISO 27001 certification, and the requirement comes from your sales process rather than from your technology.
If a single customer wants to see one Type I report, your stack is straightforward, and you have fewer than ten employees, engaging an audit firm directly without a platform can be the shorter route. The value of automation accrues across a Type II period and across repeat examinations, not on a one-off point-in-time assessment.
And if your controls are not running yet, a tool does not solve that. Security processes first, evidence of them second. A vendor selling you the reverse order is selling you examination risk.
How does Kertos cover SOC 2 preparation?
If you are a European company running SOC 2 alongside ISO 27001 and GDPR, Kertos is the obvious choice, for the two reasons that weigh heaviest in the criteria above.
Kertos runs ISO 27001, ISO 27701, ISO 42001, GDPR, NIS2, the EU AI Act, SOC 2, TISAX, and C5 on one shared control set. You store a measure once and see which Annex A requirements, which Common Criteria, and which GDPR articles it satisfies. Evidence is collected automatically through more than 100 integrations, given an expiry date, and assigned to every framework it serves. The time series a Type II report requires emerges as a by-product of ongoing operations.
The platform is operated in Germany and was built for European frameworks rather than extended to cover them afterwards. Every project is accompanied by certified experts who set the mapping up with you instead of handing it to you as a task. KAIA, the AI assistant, answers questions on control design in German and English and keeps policies current.
Figures from live operations: a 100 percent audit pass rate, roughly 80 percent less manual compliance effort, and 98 percent customer satisfaction. What Kertos covers for this framework in detail is set out on the page on SOC 2 compliance; the fundamentals of the framework are covered in the top benefits of a SOC 2 report.
In fairness: if SOC 2 is all you need, with no European frameworks alongside it, Kertos does not get to play some of its strengths. The advantage comes from the shared control set across several frameworks.
Frequently asked questions
Is there such a thing as a SOC 2 certification?
No. A SOC 2 examination produces a SOC 2 report, either Type I for a point in time or Type II for an observation period of typically three to twelve months. The term "SOC 2 certification" is widespread but technically wrong, and auditors read its use as a sign of inexperience.
Do you need software for SOC 2 preparation?
It is not mandatory. The effort, however, sits almost entirely in collecting, mapping, and refreshing evidence, and that is exactly the part that can be automated. For a Type II report there is the added requirement that evidence exists for the whole observation period without gaps. Maintaining that history by hand is the real weak point of manual approaches.
Which of the five Trust Services Criteria do I have to cover?
Only Security is mandatory, examined through the Common Criteria. Availability, Processing Integrity, Confidentiality, and Privacy are ones you add to the scope yourself. In practice SaaS providers usually choose Security together with Availability and Confidentiality, because that is what procurement asks about. The five categories are set out in the AICPA Trust Services Criteria.
Is an ISO 27001 certification enough for SOC 2?
No, but it does a large part of the work in advance. The security requirements overlap heavily; the evidence requirement differs. SOC 2 Type II calls for evidence across a period where the ISO 27001 audit works from a sample. The two procedures are also organizationally separate and are commissioned separately.
What does a SOC 2 examination cost and how long does it take?
The cost is made up of the audit firm's fee, internal effort for implementation and evidence upkeep, tooling, and where relevant external support; the duration depends mainly on the observation period you choose. Figures and timelines are covered separately under what a SOC 2 audit costs and how long it takes to reach a SOC 2 audit.
If you want to work out which of your current evidence can count toward SOC 2 and ISO 27001 at the same time, book a demo. We will go through your existing mapping together.
Discover Our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


