Why a web agency is suddenly hearing about SOC 2
SOC 2 used to be something only SaaS companies worried about. That's changing. As WordPress agencies move upmarket — landing mid-market and enterprise clients instead of purely small-business ones — they're increasingly running into a procurement or security team that asks, flatly, "do you have a SOC 2 report?" before they'll let the agency touch the client's site, hosting, or infrastructure at all. It's become a vendor-vetting checkbox in exactly the same way "do you carry insurance" already is.
This usually isn't the client being difficult. Larger organizations increasingly have their own compliance obligations — sometimes their own SOC 2, sometimes contractual security requirements from their customers — and part of satisfying those is demonstrating that every vendor with access to their systems and data meets a baseline standard too. An agency managing a client's WordPress site typically has admin-level access to that client's infrastructure, which puts the agency squarely inside the client's own vendor-risk review, whether either side calls it that or not.
What SOC 2 actually is
SOC 2 (System and Organization Controls 2) is a voluntary attestation framework created by the AICPA. It isn't a law and it isn't a certificate you can just buy — it's the result of an independent auditor examining your organization's controls against a defined set of criteria and issuing a report on what they found.
The audit is built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the one category every SOC 2 report must include — it's often called the "Common Criteria," and covers things like access control, monitoring, and change management. The other four are optional and get included only if they're actually relevant to what you do; a WordPress agency's report would typically focus on Security, and possibly Availability if uptime commitments are part of the pitch.
Type I vs. Type II — the distinction that actually matters
This is the detail that trips people up first. A SOC 2 Type I report evaluates whether your controls are appropriately designed at a single point in time — essentially, "on this date, did you have the right policies and controls in place on paper." A SOC 2 Type II report goes further: it evaluates whether those same controls actually operated effectively over an extended observation period, commonly three, six, or twelve months.
In practice, most clients who ask for "a SOC 2" mean Type II — it's the one that actually demonstrates ongoing discipline rather than a one-time snapshot. Type I is sometimes used as a faster first step (it can typically be issued within four to six weeks of remediation) before committing to the longer Type II observation window.
What SOC 2 actually asks of a WordPress-management practice
None of this is exotic if your agency already runs a tight operation — but it does require the practice to be documented and consistent, not just something everyone "basically does":
- Access control policies, formalized. Who gets admin access to which client sites, how that access is granted, and — critically — how it gets revoked when a project ends or an employee leaves. This is exactly the checklist covered in offboarding a client site securely, except under SOC 2 it needs to be a written policy with evidence that it's actually followed, not just good practice you happen to do.
- Documented incident response. A defined process for what happens when a client site is compromised — who's notified, what steps get taken, how it's recorded. This overlaps directly with the structure an incident-response retainer already requires you to think through; SOC 2 just asks you to write it down and be able to show it was followed.
- Consistent hygiene across every site, not per-project judgment calls. An auditor isn't interested in "we handle it differently depending on the client." SOC 2 wants a standard baseline — the same access controls, the same patching cadence, the same audit trail — applied uniformly, which connects directly to the discipline behind running a security audit on every new client site.
- Change management and monitoring. A record of what changed on a site and when, and some form of ongoing monitoring rather than purely reactive "we'll notice if something breaks."
What the process actually looks like
Getting to a first SOC 2 report generally follows the same rough shape regardless of company size. First comes a readiness assessment — often with a compliance-automation vendor — to see how far your current practices are from the relevant Trust Services Criteria and what needs to change. Then comes remediation: writing the actual policies (access control, incident response, change management), and, more importantly, actually running your agency by them for a while so there's something for an auditor to observe. Only after that does the formal audit happen, performed by an independent CPA firm licensed to issue SOC 2 reports — not by the compliance-automation vendor itself, whose role is usually to help you prepare and collect evidence, not to attest to it.
For a Type II report specifically, the clock doesn't really start until your controls have been operating consistently for the full observation window. That means the honest timeline from "we decided to pursue this" to "we have a report to hand a client" is typically somewhere in the range of six months to a year for a first-time SOC 2 Type II, not weeks — worth knowing before you promise a prospect a report on a shorter timeline than that.
An honest note on scope
SOC 2 is a genuine undertaking, not a weekend project. A first Type II report realistically takes months of preparation plus the observation period itself, and most agencies work with a specialized auditor and often a compliance-automation platform to get there. It also isn't something every agency needs — if your client base is small businesses and local shops, this almost certainly isn't on their radar. The honest trigger is a specific deal: a client's procurement or security team explicitly asking for it, or a pattern of larger prospects raising it repeatedly. Pursuing SOC 2 speculatively, before any client has actually asked, is usually premature — the underlying security hygiene it demands is worth having regardless, but the formal audit itself is a business decision to make when the revenue on the table justifies the cost and time.
Whatever compliance framework you're working toward, know what's actually happening across client sites first.
Install free →