
SOC 2 Type II Readiness: What Auditors Actually Test
Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

ISO/IEC 27001 remains the most widely recognised information security standard in the world. For many organisations it is no longer a differentiator but a condition of doing business: enterprise procurement questionnaires, public-sector tenders and partner due diligence increasingly ask for a valid certificate rather than a description of your controls.
The standard does not prescribe a technology stack. It requires an Information Security Management System (ISMS) — a documented, risk-based way of deciding which controls you need, operating them, measuring them and improving them. That is why a certificate carries weight: it shows that security is managed as a system, not as a collection of tools.
ISO/IEC 27001:2022 restructured Annex A. The previous 114 controls in 14 domains were consolidated into 93 controls grouped into four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are new, reflecting how estates actually operate today:
The transition period for certificates issued against the 2013 edition ended on 31 October 2025, so any organisation certifying or recertifying now does so against the 2022 edition. A 2024 amendment also asks organisations to consider whether climate change is a relevant issue when defining their context — usually a short, documented judgement rather than new controls.
Certification programmes rarely fail on technical controls. They slip because early decisions were deferred or made badly. Settle these six before you write a single policy:
| Phase | What happens | Typical duration |
|---|---|---|
| Gap assessment | Current practice compared against the clauses and Annex A; prioritised gap register | 3–4 weeks |
| ISMS design | Scope statement, policy, risk methodology, risk assessment, Statement of Applicability | 4–6 weeks |
| Implementation | Controls introduced or formalised, procedures written, owners trained | 8–12 weeks |
| Operation and evidence | Controls run and produce records — access reviews, change approvals, training, supplier checks | 8–12 weeks (overlaps) |
| Internal audit and management review | Independent internal audit of the whole ISMS; leadership review of results | 2–3 weeks |
| Stage 1 audit | Certification body reviews documentation and readiness | 1–3 days |
| Stage 2 audit | Certification body tests whether controls operate effectively | 2–6 days depending on scope |
After certification the cycle continues: surveillance audits in years one and two, and a full recertification audit in year three. The organisations that find surveillance audits easy are the ones that built evidence into daily work rather than assembling it before each visit.
Clauses 4 to 10 require specific documented information. As a minimum, expect to present:
Certification cost is driven by scope, headcount and how much already exists. The cheapest route is almost never the one with the fewest consulting days — it is the one that reuses what you already do. Most organisations already run change control, joiners-and-leavers processes and backup routines; the work is formalising them, assigning owners and keeping records.
If you also answer to SOC 2, PCI DSS, NIST CSF or regional regulators, design one control library mapped to all of them. Testing a control once and reporting it against several frameworks is where the real saving sits.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.

All future-dated requirements have been mandatory since March 2025. These are the ones assessors most often find incomplete — and what good evidence looks like.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.