SOC 2 Type 2 Certification Key Requirements
Last updated: March 9, 2026
To complete your SOC 2 Type 2 certification, there are several key requirements that need to be fulfilled. Here's what you need to know about the process and requirements.
Key Requirements for Type 2 Certification
The following items must be completed for your SOC 2 Type 2 audit:
Access Reviews - Review of critical and high-priority services (such as GCP, Auth0, Stripe, Github, and Google Workspace)
Restoration Testing - Test restore of your environment with documentation via screenshots
Firewall/Network Configuration Review - Network security configuration assessment
Security Awareness Training and Policy Sign-off - Completion of required training and policy acknowledgments
Policy Updates - Ensure all security policies are finalized and not in draft status
Completing Access Reviews
Access reviews can be started before the formal Type 2 audit begins. You can complete these using the access review feature in the platform at https://app.mycroft.io/access-reviews/.
For services like Github, you have two options:
Use the Github integration at
https://app.mycroft.io/integrations/github/configureProvide screenshots of user lists if the integration scope is too broad
When providing user information, include:
Full names
Contact emails
Job titles
Employment status (employee, contractor, intern)
Start dates for new team members
Restoration Testing
For restoration testing, you can use a development environment to demonstrate that your database backups are restore-ready. Document the process with screenshots showing the restoration walkthrough.
Policy Requirements
Ensure all security policies are finalized and published before the audit. Policies cannot remain in draft status during the Type 2 certification process. Read our article on policy reviews and sign-offs for SOC 2 to learn more.
Timeline Considerations
The Type 2 certification process can begin once all preliminary requirements are met. Access reviews are typically quick to complete and can be done ahead of the formal audit start. Other requirements like restoration testing and network configuration reviews will need coordination with your audit team. Read our article to learn more about SOC 2 timeline considerations.