INSIGHTS

A Client Asked for a SOC 2 Report. Now What?

A client requested SOC 2. Learn what to ask, how Type I and Type II differ, what affects cost, and how Dozer helps with readiness and AI data protection.

Leo AlcantarSeptember 4, 2026

Leonardo Alcantar

Illustration of a SOC 2 request in a gold envelope beside an evidence checklist and magnifying glass.

If a client asks for a SOC 2 report, first confirm whether they require Type II or would accept other security evidence. Then define the scope, review your existing controls, and plan any preparation work with an independent CPA firm. Dozer Systems helps with readiness, documentation, technical controls, and auditor coordination.

A new client wants to work with your business. Before moving forward, they ask for a SOC 2 Type II report, or something similar, to show that their information will be protected.

Maybe they also want to know whether your employees use AI and where their data goes when they do.

You already have security tools, an IT provider, and procedures for handling sensitive information. But you do not have a formal SOC 2 report. What should you do next?

What should you ask when a client requests SOC 2?

Before committing to an audit, clarify the request. Does the client specifically require a SOC 2 Type II report? Or are they asking for evidence that your business handles information responsibly?

  • Is SOC 2 a firm requirement, or an example of acceptable security documentation?
  • Which services, systems, and client information does the request cover?
  • Is there a deadline?
  • Would they consider supporting security documentation while you work toward a formal examination?
  • Are there specific requirements for AI use and data handling?

Their answer determines the next step. A security questionnaire, documented policies, and supporting evidence may address an immediate request if the client accepts them. Those materials do not replace a SOC 2 report when the report itself is required.

What does a SOC 2 report actually tell a client?

SOC 2 is an independent examination of controls for a defined system against applicable AICPA Trust Services Criteria. Its scope can address security, availability, processing integrity, confidentiality, and privacy.

It gives customers information they can use to evaluate how a service organization manages the systems and information entrusted to it. It does not guarantee that a security incident can never happen. See AICPA's SOC resources.

What is the difference between SOC 2 Type I and Type II?

  • Type I: Evaluates whether the controls are suitably designed at a specified date.
  • Type II: Evaluates whether the controls are suitably designed and operated effectively over the period examined.

A licensed independent CPA firm performs the examination and issues the report. Dozer helps your organization prepare for that process. The report applies to its defined scope and period, so customers should check that it covers the services they use. See AICPA's SOC 2 report review checklist.

We already have cybersecurity. What else is involved?

Your existing security program can give you a useful starting point. Access controls, device management, monitoring, backups, and employee onboarding procedures may already support the work ahead.

Preparation involves checking those practices, documenting responsibilities, addressing gaps, and retaining evidence.

For example, disabling an account when someone leaves is a security practice. Supporting evidence might include the departure notification, the account removal record, and confirmation that access to relevant applications was removed.

The same distinction applies to access reviews, backup testing, security training, and incident response. A written policy describes what should happen. Records help demonstrate what actually happened.

There can also be work outside IT, including management approvals, employee processes, and vendor oversight. Your leadership team remains responsible for the organization's policies, decisions, and controls.

How does Dozer help with SOC 2 readiness?

Dozer helps turn a customer's request into a defined preparation project. Depending on your environment and requirements, that work can include:

  • Clarifying scope: Identify the services, systems, data, and business processes involved.
  • Reviewing existing controls: Determine what is already working and what needs attention.
  • Addressing gaps: Improve technical safeguards and operating procedures where needed.
  • Formalizing policies: Document practices your team can realistically follow and maintain.
  • Organizing evidence: Establish who collects records, where they are stored, and how they are reviewed.
  • Documenting AI and data handling: Explain where information goes and how access is controlled.
  • Coordinating with the auditor: Help your team respond to requests from the independent CPA firm.

When Dozer already provides your managed IT and cybersecurity services, our familiarity with the environment can help with preparation. We still assess readiness before making commitments about timing or effort.

What if the client asks whether our AI is closed loop?

Start by defining what they mean. They may want assurance that their information is not used to train a provider's models, cannot be accessed by other customers, or stays within an approved environment. Those are separate requirements.

To answer accurately, we examine questions such as:

  • What information can employees submit to AI tools?
  • Where does processing occur, and which providers receive the data?
  • Are prompts, uploaded files, or outputs retained?
  • Can the data be used for model training?
  • Who can access the information?
  • What can connected applications retrieve or share?

An AI product's name or a private label is not enough to answer those questions. The answer depends on the service, configuration, contractual terms, and actual workflow.

Dozer can help document that workflow and identify controls needed to support your commitments. This approach is consistent with NIST's emphasis on managing privacy, information security, and third-party risks in generative AI. See NIST's Generative AI Profile.

A SOC 2 report also needs to cover the relevant systems and controls before you rely on it to answer an AI-specific question.

Should we work toward Type II even if this client does not require it?

It can be worthwhile when formal security reviews are becoming a recurring part of winning or keeping business.

Consider the customers you serve, the information you handle, upcoming contracts, and the time your team spends responding to security reviews. Also consider the ongoing work required to maintain controls and prepare for future examinations.

The right decision depends on those factors. An immediate documentation request and a longer-term SOC 2 plan can be handled separately.

How long does SOC 2 preparation take?

The schedule depends on your starting point, the scope, gaps to address, and the CPA firm's examination plan. Type II requires evidence of controls operating over a period of time, so it cannot be completed simply by writing policies at the last minute.

Discuss the examination period and evidence expectations with the CPA firm early. A Type I report may be useful as an interim step if customers accept it, but it is not a prerequisite for Type II.

What does SOC 2 cost?

A useful budget separates preparation from the independent examination.

Preparation may include policy development, evidence collection, control improvements, and project coordination. Additional costs can include auditor fees, software, testing, and your own team's time.

The total depends on scope, complexity, existing practices, and the gaps that need to be addressed. It should also account for ongoing maintenance and future examinations.

Formal compliance preparation is scoped separately from routine managed IT and cybersecurity services. Dozer defines that work before providing a project estimate.

Can Dozer help with other compliance frameworks?

The same starting questions apply: What is required, what is in scope, and what evidence is expected?

ISO/IEC 27001 sets requirements for an information security management system and can involve independent certification. The NIST Cybersecurity Framework helps organizations organize and prioritize cybersecurity risk management. These serve different purposes and are not interchangeable with SOC 2.

Dozer can help assess the applicable technical and operational requirements, map existing controls, identify gaps, and prepare documentation. The assessment or certification process depends on the requirement involved.

Have a SOC 2 request? Start with the message you received.

You do not need to have the entire compliance process figured out before asking for help.

Bring us the questionnaire, contract language, or security request. We can help clarify what the client needs, review what you already have, and determine the work required to respond.

Based in Minneapolis, Dozer Systems supports businesses across the Twin Cities and nationwide. Contact Dozer Systems to discuss a SOC 2 request, compliance readiness, or questions about protecting client information in AI workflows.