A SOC 2 report is an attestation by a licensed CPA firm on your controls against the AICPA Trust Services Criteria. Teddy's agents define the system, map your controls and collect evidence across the whole observation period. A compliance engineer takes you to the auditor.

SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report your customers can read. Here is what goes into it and where it lives in Teddy.
Security, with the common criteria CC1 to CC9, is always in scope. Availability, confidentiality, processing integrity and privacy are added when they matter to your customers.
Your services, infrastructure, software, people, data and procedures in scope, including subservice organizations such as your cloud provider.
Control environment, communication and information, risk assessment, monitoring activities and control activities. The base the technical controls rest on.
Logical and physical access, system operations, change management and risk mitigation, including vendors and business disruption.
A Type I report covers the design of controls as of one date. A Type II report also tests whether they operated effectively over a period, typically three to twelve months.
The auditor’s opinion, management’s assertion and the system description. A Type II report adds the tests performed and any deviations found.
A Type II report looks back over the whole period. A control that did not run cannot be evidenced afterwards, and every deviation the auditor finds is described in the report your customers read.
Teddy drafts the description of your system from how your product actually runs.
The Evidence Agent collects proof for every month the auditor will check.
Connect your cloud, login, HR and code tools once. Access is read-only.
Someone takes screenshots the week before fieldwork, the June logs have expired and the access review lives in a spreadsheet. ChatGPT can explain CC7.2, but it cannot see whether you ran it. Teddy collects evidence from your systems throughout the period and flags a missing record while you can still respond.
AuditorPlease send access review records for all six months.
Lukas · EngineeringThe June access review? I think we skipped it.
Ben · SalesThe prospect wants our SOC 2 report before signing.
Nina · OperationsScreenshotting 40 consoles again this week.
Sarah · CEOWill there be exceptions in the report?
Teddy's agents prepare and run the program. You approve, the audit firm examines, and a compliance engineer is with you through fieldwork.
Teddy asks what your customers expect and which systems deliver your service, then proposes the Trust Services Criteria, the report type and the observation period.
Teddy maps your controls to each criterion you selected and shows where a criterion has no control yet or a control has no owner.
The Policy Agent drafts policies and the system description from your setup, so both describe how your service actually runs.
The Evidence Agent collects records from connected tools on a schedule. A missing record shows up while you can still document it, not during fieldwork.
Controls you already run for ISO 27001, TISAX® or NIS2 count for SOC 2 too. Teddy maps every framework onto one control set and shows only what is new.
Ask in plain language what the auditor will test. Teddy answers from your live program and does the work. For fieldwork, our compliance engineers are at your side.
Ask TeddyWhich criteria do we need? What will the auditor sample? Teddy knows the criteria and your controls.
Agents do the workMapping, system description, evidence and management responses arrive ready for your approval, each with its source.
Our team backs you upCompliance engineers help you choose an audit firm and join you through fieldwork.
No. SOC 2 is an attestation report. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and gives its opinion. Teddy prepares the program and the evidence, the audit firm forms the opinion.
A Type I report covers the design of your controls as of one date. A Type II report also tests whether they operated effectively over a period. Enterprise customers usually ask for Type II.
A lot. Teddy maps both onto one control set. SOC 2 adds the system description, the criteria you select and testing over the observation period.
A Type II report covers one period. Most companies start the next period right away, so their reports follow each other without a gap. For the time until the next report, management can issue a bridge letter. Teddy keeps collecting evidence throughout.
Start with a gap audit against the Trust Services Criteria.
Reviewed by Sven Moritz, former CISO · October 2026
Readiness work takes months before the observation period even starts. First-time remediation and evidence often take 4 to 16 weeks on their own.
Your observation period can start right away. Controls are mapped to the Trust Services Criteria and evidence runs from day one. A Type 1 can follow immediately.
Skip one quarterly review in a Type 2 period and the report lists it as an exception. Three clean quarters do not cancel it out. Auditors test whether you did what your own policy says, so set a cadence you can keep.
The auditor samples production deployments from the whole period. Emergency changes without a review afterwards are a frequent exception in engineering-heavy teams.
Offboarding is written down, but there is no ticket showing access was removed on time. Evidence has to be collected during the period, not reconstructed at the end.