SOC 2 Type 2 Certification Key Requirements

Last updated: March 9, 2026

To complete your SOC 2 Type 2 certification, there are several key requirements that need to be fulfilled. Here's what you need to know about the process and requirements.

Key Requirements for Type 2 Certification

The following items must be completed for your SOC 2 Type 2 audit:

  • Access Reviews - Review of critical and high-priority services (such as GCP, Auth0, Stripe, Github, and Google Workspace)

  • Restoration Testing - Test restore of your environment with documentation via screenshots

  • Firewall/Network Configuration Review - Network security configuration assessment

  • Security Awareness Training and Policy Sign-off - Completion of required training and policy acknowledgments

  • Policy Updates - Ensure all security policies are finalized and not in draft status

Completing Access Reviews

Access reviews can be started before the formal Type 2 audit begins. You can complete these using the access review feature in the platform at https://app.mycroft.io/access-reviews/.

For services like Github, you have two options:

  • Use the Github integration at https://app.mycroft.io/integrations/github/configure

  • Provide screenshots of user lists if the integration scope is too broad

When providing user information, include:

  • Full names

  • Contact emails

  • Job titles

  • Employment status (employee, contractor, intern)

  • Start dates for new team members

Restoration Testing

For restoration testing, you can use a development environment to demonstrate that your database backups are restore-ready. Document the process with screenshots showing the restoration walkthrough.

Policy Requirements

Ensure all security policies are finalized and published before the audit. Policies cannot remain in draft status during the Type 2 certification process. Read our article on policy reviews and sign-offs for SOC 2 to learn more.

Timeline Considerations

The Type 2 certification process can begin once all preliminary requirements are met. Access reviews are typically quick to complete and can be done ahead of the formal audit start. Other requirements like restoration testing and network configuration reviews will need coordination with your audit team. Read our article to learn more about SOC 2 timeline considerations.