Skip to content

Häufig gestellte Fragen

What is the difference between SOC 2 Type 1 and Type 2?
A SOC 2 Type 1 report assesses a provider's internal controls at a single point in time and only examines whether they are adequately described and suitably designed. A Type 2 report goes considerably further and examines, over an observation period of at least three and typically six to twelve months, whether the controls were actually effective throughout. Type 2 therefore carries significantly greater weight and is regularly required by enterprise customers in procurement processes. For evaluating a cloud-based ERP provider, the Type 2 report is consequently almost always the relevant basis.
Is ISO 27001 enough, or do I need SOC 2?
Both attestations demonstrate information security but differ fundamentally: ISO 27001 is an international standard that certifies an information security management system and results in a standardised certificate, whereas SOC 2 is a detailed, individual audit report from the US-based AICPA without certificate status. SOC 2 is more commonly expected in the US market, while ISO 27001 is more widespread in Europe, which is why many internationally active cloud and ERP providers maintain both attestations. Which one is sufficient for you depends on your own customers, your industry and regulatory requirements. It is advisable to clarify the need together with your own compliance and procurement stakeholders rather than committing to one standard across the board.
How much does a SOC 2 audit cost?
The pure auditor fees for a SOC 2 Type 2 report usually range between around 20,000 and 80,000 US dollars, depending on provider size, scope and the number of Trust Services Criteria examined, and can go higher in larger organisations. A simpler Type 1 report is cheaper and often starts in the low five-figure range. On top of that come internal preparation costs and frequently a separate readiness assessment, which can cost anywhere from several thousand to over ten thousand US dollars. Since these figures depend heavily on the individual starting position, they should be understood as rough guidance rather than fixed prices.
How long is a SOC 2 report valid?
A SOC 2 report does not formally “expire”, but it only ever covers the audit period stated in it and is in practice considered meaningful for around twelve months. Providers therefore usually have the report renewed annually so that it connects seamlessly to the preceding period. For the time between the end of one report and the next, many providers issue a so-called bridge letter, which generally covers a maximum of about 90 days and confirms that nothing material has changed in the control environment. When selecting a provider, you should therefore check whether the report presented is current and whether the audit period contains any gap.
Which Trust Services Criteria does a SOC 2 report cover?
SOC 2 is based on five Trust Services Criteria defined by the AICPA: security, availability, processing integrity, confidentiality and privacy. Only the security criterion is mandatory in every SOC 2 report; the other four are examined only if they are relevant to the respective service or have been committed to by the provider. For an ERP system, security, availability and confidentiality matter most in practice, since business-critical data must be permanently accessible and protected from unauthorised access. When reading a report, you should therefore always check which of these criteria are actually included in the audited scope.
Does a SOC 2 report replace a GDPR assessment?
No, SOC 2 is a US audit framework and does not automatically cover European data protection obligations. Even where the privacy trust services criterion is part of a report, it replaces neither an assessment under the GDPR nor the required data processing agreement with the provider. Rather, a SOC 2 report provides independent evidence that the committed security and availability controls are effectively implemented, and should be viewed as one building block in an overall picture of certificates, contracts and your own risk assessment. For the data protection assessment of a cloud-based ERP system, the relevant GDPR requirements must therefore be considered in addition.