Skip to content
Cloudreason

SOC 2 on AWS: controls, evidence and the Type II window

A Type II report grades the whole observation window, not the audit day.

SOC 2 · AWS

Published

SOC 2 rarely starts as your idea. It arrives from outside: an enterprise prospect’s security review, a US customer’s procurement gate, a due diligence checklist ahead of a funding round. For UK software businesses on AWS it has become the second framework alongside ISO 27001, and the one where the difference between looking compliant and operating compliantly is written into the report itself.

A report, not a certificate

SOC 2 is an attestation defined by the AICPA, the US accountancy body, and delivered by a licensed CPA firm. There is no certificate and no badge; the deliverable is a report, and your customers will read it. The report assesses your controls against the Trust Services Criteria: security is mandatory, and availability, confidentiality, processing integrity and privacy are added as your customer commitments require. Most SaaS platforms scope security, availability and confidentiality.

The distinction that matters commercially is Type I versus Type II. Type I says your controls were suitably designed on a given day. Type II says they operated effectively across an observation window, typically six to twelve months. Sophisticated buyers ask for Type II, and increasingly specify a minimum window.

What AWS’s own SOC reports settle

AWS publishes SOC 1, 2 and 3 reports for its infrastructure, available through AWS Artifact, and your auditor will rely on them for the layers AWS operates: physical security, the hypervisor, the underlying network. AWS is treated as a subservice organisation, normally under the carve-out method, meaning its controls sit outside your report but your reliance on them is documented.

What that does not do is shrink your side of the shared responsibility model. The AWS SOC 2 report contains a list of complementary user entity controls: things AWS explicitly expects its customers to do, from configuring access control to encrypting data and monitoring their own workloads. Your auditor has read that list and will check you against it.

Mapping the criteria to an AWS estate

The common criteria translate onto AWS services directly, and most of the evidence can be generated as a by-product of running the estate well:

  • Logical access (CC6). IAM and IAM Identity Center for least privilege, multi-factor authentication, and joiner-mover-leaver records. Access reviews need to exist as records, not as a policy that claims they happen.
  • System operations (CC7). CloudTrail, GuardDuty and Security Hub for monitoring and anomaly detection, with triage records showing alerts were investigated. Incident response needs at least one exercised, documented run.
  • Change management (CC8). Infrastructure as code with review and approval in the pipeline, and AWS Config to catch changes made around it. The unreviewed console change is the classic Type II exception.
  • Availability. Multi-AZ design, AWS Backup with tested restores, and capacity monitoring. A backup that has never been restored is a hope, not a control.
  • Confidentiality. KMS for encryption and key lifecycle, data classification, and retention and disposal that provably happen.

The observation window is the audit

The property that makes SOC 2 different from every point-in-time assessment is that a Type II report grades the whole window. The auditor samples across the period: access reviews from March, change records from June, alert triage from September. A month where logging was off, or a quarter of skipped reviews, does not get fixed before the audit; it becomes an exception, printed in the report your customers read.

That makes SOC 2 structurally hostile to the scramble-before-the-audit model that annual frameworks tolerate. The estate either operates its controls continuously, or the report says so. This is the model Cloudreason’s cloud compliance service is built for: continuous monitoring against your control set, remediation carried out by our engineers, and evidence accumulating throughout the window rather than reconstructed at the end of it. If a customer has just asked for your SOC 2 report and you do not have one, talk to us about the fastest honest route to a clean Type II.

← Cloud Compliance at Cloudreason

Frequently asked questions

What is the difference between SOC 2 Type I and Type II?

A Type I report assesses whether your controls were suitably designed at a single point in time. A Type II report assesses whether they actually operated effectively across an observation window, typically six to twelve months. Enterprise customers almost always want Type II, because a control that existed on one Tuesday proves very little.

Does AWS's SOC 2 report cover my platform?

No. AWS publishes its own SOC reports for the infrastructure it operates, and your auditor will treat AWS as a subservice organisation, normally excluded from your report under the carve-out method. Your access control, change management, monitoring and backup controls are assessed as yours, and the AWS report itself lists the complementary user entity controls it expects you to have implemented.

How is SOC 2 different from ISO 27001?

ISO 27001 is a certification against a management system standard, audited by a certification body on a three-year cycle. SOC 2 is an attestation report written by a CPA firm describing your controls and, in a Type II, how they operated over a period. US-led procurement tends to ask for SOC 2, international procurement for ISO 27001, and most UK SaaS businesses selling into both markets end up running one control set that feeds both.

How long does it take to get a first SOC 2 report?

Realistically six to twelve months from a standing start: a readiness assessment, remediation of the gaps it finds, an observation window that is often three months for a first report, then the audit itself. The window cannot be compressed retrospectively, so the start date is the deadline that matters.

Got an audit date?

Tell us the date and the framework, and we'll tell you honestly what stands between your estate and passing.