Earlier quoted context omitted.
Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…
I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.
But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.