
By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · September 2026 · 8 min read
Is SOC 2 enough to call your company secure? No. A SOC 2 report is an independent auditor's opinion on the controls you put in scope, and for a Type 2, on whether they worked during a review window. It tells a customer you run a real program. It does not tell anyone that an attacker cannot walk in tonight.
That distinction matters more this year than it ever has. Founders are shipping AI features at a pace nobody planned for, enterprise buyers answer by asking for a SOC 2 report, and the fastest route to that PDF is often a consultant who writes the policies, runs the readiness work and hands the company a finished package. We broke down what SOC 2 actually costs in Canada separately. That budget buys the report. It does not buy the protection around it. The report arrives. The team moves on. And in a lot of the companies our team talks to, the basics that actually stop a breach were never part of the project.
The AICPA describes SOC 2 as a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality or privacy. Read that sentence slowly. It is a report on controls, and the controls are the ones you describe to the auditor.
Three things follow from that.
You choose the scope. A company can put its main product in scope and leave out the support portal, the contractor laptops or the old admin console nobody uses anymore. The auditor tests what is described. What sits outside the description is outside the opinion.
A Type 2 looks backward. It covers a review window that has already ended. It says the controls operated during that period. It says nothing about the morning after the window closed.
A clean opinion is not a finding that you are secure. It means the controls you described were designed and, for a Type 2, operated the way you said. If the controls were thin, the report can still be clean.
None of this is a flaw in SOC 2. It was never built to be a guarantee. The problem starts when a company treats it like one.
PowerSchool is the clearest public example. Its own security page says it receives annual SOC 2 Type 2 examinations on its controls for multiple applications and holds ISO 27001:2022 certification. That is a mature program by any standard.
In December 2024, an attacker used a single compromised credential to get into PowerSource, a customer support portal, and from there reached student and teacher records held for school districts, including boards across Ontario. PowerSchool told TechCrunch that the portal did not support multi-factor authentication at the time. The same TechCrunch report says the forensic investigation found someone had used the same credentials months earlier, from August to September 2024, and could not say whether it was the same actor because of insufficient logs.
Look at what that sentence contains. A login without MFA. An intruder nobody caught for weeks. Logs too thin to tell the story afterward. The certifications were real, and so was every one of those gaps.
The same pattern shows up at Change Healthcare. According to Cybersecurity Dive's coverage of the congressional testimony by UnitedHealth's chief executive in 2024, the company's policy was to have MFA turned on for all external facing systems, yet the remote access portal the attackers used did not have it. The policy existed. The control was missing on one server.
When we sit with founders who already hold a SOC 2 report, or are paying for one, the same four gaps come up again and again. None of them is exotic, and none of them needs a large security team.
1. Managed detection and response on every endpoint. Someone has to be watching laptops and servers for attacker behavior, day and night, and be able to isolate a machine when something looks wrong. The Canadian Centre for Cyber Security's Top 10 IT Security Actions tell organizations to monitor intrusion prevention alerts and logs for signs of intrusion. A policy that says "we monitor" is not the same as a person reading the alert at 2 a.m.
2. Email security that stops the message before a person has to. Many attacks still start in an inbox. The Canadian Centre for Cyber Security's ransomware playbook recommends SPF, DKIM and DMARC to stop spoofing, alongside training so staff recognize phishing. Training helps. Filtering the fake invoice before accounting ever sees it helps more.
3. Identity threat detection. Stolen credentials are the common thread in both stories above. MFA on every external login is the floor, and the same CCCS Top 10 guidance says to use it wherever possible for all users and applications. Above that floor, you want something that flags the login that should not happen: a new country, an impossible travel time, a fresh admin account nobody requested.
4. A backup you have actually restored. Code Spaces, a code hosting company, learned this in 2014. An attacker who got into its cloud control panel deleted data, backups and offsite backups from the same console, and the company told customers it could not continue operating, as Help Net Security reported at the time. The CCCS ransomware playbook recommends keeping backups offline, out of reach of your network, and testing them on a regular schedule, for example monthly. A backup policy in the SOC 2 binder is not a restore that worked last month.
If you are building AI products, add one more line to that list. Your model and its prompts are part of the attack surface now, and testing them is its own discipline. Our sister product covers AI red teaming for that side of the problem.
For winning the deal, often yes. For surviving the week an attacker picks you, no.
Keep the report. Buyers ask for it for good reasons, and a well run SOC 2 program forces discipline that most small teams would never build on their own. But treat it as the minimum a customer asked to see, not the finish line.
The better question for a founder is whether you can show, on any given day, that MFA covers every external login, that someone is watching for suspicious sign-ins, that your email is filtered and authenticated, and that your last backup restore actually worked. That is evidence, and a good auditor will ask for most of it anyway. The companies that come through audits and incidents well are the ones whose evidence is real every week, not assembled once a year for the review window.
A few honest checks, whichever consultant or platform you used. Our SOC 2 compliance checklist for Canadian companies goes through the full control list if you want the long version:
If those answers are uncomfortable, the report is doing its job as a sales document and very little as protection.
Being straight about our role. We are not an auditor and we do not issue SOC 2 reports. A licensed CPA firm does that, and it should stay that way. No software product can hand you a SOC 2.
What we build is the software that gets your evidence in order long before anyone shows up to test it, so your team understands its own controls instead of inheriting a binder. If you want the full picture of the report types first, our guide to SOC 2 Type 1 versus Type 2 explains what each one tests, and our SOC 2 compliance page covers how we help Canadian teams prepare.
Is SOC 2 enough to prove my company is secure?
No. A SOC 2 report is an auditor's opinion on the controls you put in scope and, for a Type 2, on whether they worked during a past review window. It shows a customer you run a real program. It does not show that every system is protected today or that someone is watching for attackers.
Can a company with a SOC 2 Type 2 report still be breached?
Yes. PowerSchool held annual SOC 2 Type 2 examinations and ISO 27001 certification, and in December 2024 an attacker used one compromised credential on a support portal that, the company told TechCrunch, did not support multi-factor authentication.
What security should a startup run beside SOC 2?
At minimum: managed detection and response on endpoints, email security with SPF, DKIM and DMARC, identity monitoring with MFA on every external login, and offline backups that are restored on a schedule. The Canadian Centre for Cyber Security recommends each of these in its public guidance.
Is it a problem to use a consultant for SOC 2?
Not in itself. Good consultants are valuable. The risk is a delivered package that nobody on the team understands, with controls that exist on paper and not in daily operation. Your team should be able to explain every in-scope control without the consultant in the room.
Does SecuritComply issue SOC 2 reports?
No. Only a licensed CPA firm can issue a SOC 2 report. SecuritComply is software that helps your team organize policies and evidence so you are ready when the auditor arrives.
SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.
Start Free →