What is SOC 2?
SOC 2 is the AICPA's attestation framework for service organizations. A CPA firm reviews your controls and produces a confidential report your prospects and customers can rely on. It's an attestation, not a certification — there's no public badge, but the report carries the AICPA's authority.
There are five Trust Services Criteria (TSCs). Security — the Common Criteria — is required. The other four are optional based on what your service actually does:
Availability — system uptime and reliability.
Confidentiality — protecting non-personal sensitive information.
Processing Integrity — data is processed accurately and on time.
Privacy — handling personal information per stated commitments.
For most MSPs, the right scope is Security + Availability + Confidentiality. That trio answers what enterprise procurement teams actually ask: will their controls protect us, will the service stay up, and will our confidential data stay confidential? Add Processing Integrity or Privacy only if your services genuinely involve those categories.
Why SOC 2 matters for MSPs
Here's a contrarian take: SOC 2 is easier for an established MSP than for a SaaS startup, even though SaaS gets the marketing attention. You already operate the controls SOC 2 evaluates. MFA, EDR, encrypted backup, monitored access, change management, vendor management — your stack passes audit because that's the job.
The work isn't operational; it's documentary. You need policies that match what you actually do, evidence captured the right way, and the discipline to gather it consistently. That's where most MSPs stumble — not because the controls aren't there, but because the controls aren't provable.
That's what Cyber Verify is for: turning the controls you already operate into evidence an auditor will accept. CVAT maps your existing UCS controls to SOC 2's Common Criteria automatically — same control, satisfying multiple frameworks. Once your first SOC 2 lands, ISO 27001, HIPAA, and CMMC are dramatically faster.
Type I vs Type II
Type I is a snapshot — it confirms the controls existed and were designed appropriately on a specific date. Type II is a movie — it confirms the controls operated effectively over a defined period (typically 3 to 12 months).
For RFPs and vendor management, prospects only care about Type II. Type I has its place — a useful milestone showing your controls are real, and it kicks off the Type II observation window. But on its own it's not the document a Fortune 500 procurement team is going to accept.
Practical sequence for an MSP starting fresh: Type I in months 4–6 (after readiness work), then a 3–6 month Type II observation window, with the Type II report arriving around months 9–12. With Cyber Verify, that timeline often compresses — most of the controls are already in place, so the work is documenting and proving them, not building from scratch.
MSP Verify + SOC 2: stronger together
SOC 2 answers "is this organization secure?" — the AICPA-standard checkbox enterprise procurement looks for. MSP Verify, built on the Unified Certification Standard, answers a different question: "is this MSP run well?" Strategic planning, internal audits, customer transition continuity, billing accuracy, business continuity — things SOC 2 doesn't even ask about.
For an MSP, having both is a real signal. SOC 2 to clear procurement. MSP Verify to differentiate among MSPs. Same evidence base, sequential audits, two badges in every sales conversation.