A few years ago "do you have SOC 2?" was a question European software companies heard only from the largest US enterprises. Today it sits in almost every security questionnaire sent by a serious American buyer, and increasingly by global companies headquartered elsewhere that have adopted US procurement practice. For SaaS products, IT-service providers, fintechs and development studios in the EU, the UK, Switzerland and the wider region, SOC 2 has moved from "nice to have" to a condition for being shortlisted. Here is what that means in practice for a company operating from Europe.
Why SOC 2 and not just ISO 27001
Most European companies that take security seriously already hold or are working towards ISO 27001. So the first reaction to a SOC 2 request is often "we are certified, is that not enough?" Usually it is not. The US market is built around SOC 2, a framework of the American Institute of Certified Public Accountants (AICPA). When an American enterprise gives you access to its data or infrastructure, its vendor risk team wants a report it knows how to read: a system description, a control list and the auditor's test results, with exceptions spelled out. An ISO 27001 certificate is accepted too, but typically as a complement rather than a substitute.
For European companies selling to both their home market and the US, the most rational path is to combine SOC 2 and ISO 27001 in a single project: roughly 70–80% of policies and controls overlap, and evidence is collected once for both purposes. If you already hold ISO 27001, most of the readiness work for SOC 2 is already done; what remains is the system description, criterion-specific controls and the evidence discipline that Type 2 demands. See SOC 2 vs ISO 27001 for the detailed comparison.
Who in Europe actually needs SOC 2
- B2B SaaS products. As soon as you sell to US mid-market and enterprise buyers, SOC 2 Type 2 becomes a standard procurement requirement, often written into the MSA.
- IT-service, software development and managed-service providers. Clients in regulated sectors (fintech, healthcare, insurance) are obliged to assess vendors, and SOC 2 is the simplest way to pass that assessment.
- Fintech and payment companies. US banks and payment partners expect SOC 2 alongside PCI DSS, and often ask for the Processing Integrity criterion.
- Companies processing personal data of US and EU customers. Here SOC 2 is usually paired with GDPR compliance; see SOC 2 and GDPR together.
- Start-ups raising capital or preparing for acquisition. US investors and acquirers treat security process maturity as part of due diligence.
What is specific about SOC 2 for a European company
Distributed and remote teams
European tech companies routinely have engineers spread across several countries, with a mix of employees and contractors. This is not an obstacle for SOC 2, but it requires explicit controls: device management, VPN or zero-trust access, full-disk encryption on laptops, a remote-work policy. The auditor does not require an office; they require evidence that access to customer data is controlled regardless of location.
Contractors and freelancers
Working with developers through their own companies or as freelancers is common across Europe, but to an auditor they are contractors, not employees. You need contracts with confidentiality clauses, signed policy acknowledgements, background screening proportionate to the role, and the same access provisioning and revocation procedures as for staff.
Data residency and subservice organisations
Many European products host in EU regions of AWS, Azure or Google Cloud for GDPR reasons. SOC 2 has no problem with that: the cloud provider becomes a subservice organisation, and its own SOC 2 report covers physical and infrastructure controls through the "carve-out" method. What you must describe is which controls are yours and which you rely on the provider for.
Existing European frameworks
ISO 27001, GDPR, NIS2, DORA for financial entities and Cyber Essentials for UK contracts can all share a control base with SOC 2. The risk is maintaining five parallel documentation sets; the answer is one control framework mapped to each requirement.
Legal structure
If you have entities in several countries, the report scope can cover only the part that delivers the service to US customers. This simplifies the audit and reduces the fee.
How the SOC 2 process looks
- Gap analysis and scoping. Which systems, which Trust Services Criteria, which report type.
- Readiness. Policies, controls, training, cloud configuration, evidence collection. Full detail in our SOC 2 readiness checklist.
- Type 1 audit (optional) confirms control design at a point in time.
- Observation period of 3–12 months during which controls must operate.
- Type 2 audit by the independent CPA firm and issuance of the report.
- Maintenance: annual renewal and a bridge letter between reports.
What US customers ask in security questionnaires
Even before you hold a report, it helps to understand what a vendor risk team is looking for. A typical questionnaire (SIG, CAIQ or a home-grown spreadsheet) contains 100–300 questions about access control, encryption, incident response, business continuity, personnel screening and subprocessors. Having a SOC 2 report lets you answer most of them with a single reference to the report instead of filling in a new questionnaire for every prospect. For companies with dozens of enterprise customers, the time saved by sales engineers and security staff alone often pays for the project.
Remember, too, that a SOC 2 report contains a section written by your company: the system description. This is where you explain how the product works, where infrastructure is hosted, which subservice organisations are involved and how support is organised. A well-written system description doubles as a marketing document read by technical decision-makers.
Who issues the report and what the consultant does
The division of roles matters. SOC 2 is not a certificate: it is an attestation report, and only a licensed US CPA firm working under AICPA attestation standards can issue it. A consultant cannot "issue SOC 2"; if someone promises that, treat it as a warning sign.
Within the BALTUM group the roles are split accordingly. The EU-based consulting team prepares the company: analysis, documentation, control implementation, evidence collection and audit support. The report is issued by the group's US-registered CPA firm, whose licensed CPA auditors form a separate team with independence safeguards, and who are used to working with European companies across time zones, in English, and with EU-hosted infrastructure. Where ISO 27001 is in the same project, the certificate is issued by the group's accredited certification body.
What SOC 2 costs for a European company
| Component | Indicative range | Depends on |
|---|---|---|
| Readiness | scope-dependent | number of gaps, team size, number of systems, existing ISO 27001 |
| Type 1 audit (CPA firm) | ≈ $8–20k | scope, number of TSC categories |
| Type 2 audit (CPA firm) | ≈ $15–40k | scope, length of observation period |
| Tooling (if needed) | a few thousand per year | automation platform, scanners, pentest |
Set against the value of a single lost US enterprise contract, these numbers are usually modest. A full breakdown is in how much SOC 2 costs.
Questions European companies ask most often
Do we need a US legal entity?
No. SOC 2 is not tied to the jurisdiction of the service organisation. A German, Polish, Spanish, Estonian or Swiss company can obtain a report on the same terms as a US one.
We already have ISO 27001. How much extra work is SOC 2?
Typically a few months of incremental work: mapping existing controls to the TSC, writing the system description, adding criterion-specific controls and establishing continuous evidence collection. Much less than starting from zero.
Can we start small?
Yes. The typical path is Type 1 covering Security, then expanding to Type 2 and additional criteria when customers ask for them.
Will SOC 2 satisfy UK clients?
Partly. In the UK, Cyber Essentials is a common requirement; it can be added to the project separately; see Cyber Essentials certification explained.
If your US customers are already asking about SOC 2, or you are preparing to enter the US market, request a quote. We will assess your readiness, propose the right scope and introduce you to the group's US CPA audit team.