Skip to main content

folkfox

Skip to main content
Skip to content
COMPLIANCE & CERTIFICATION

SOC 2 Type 2 Certification Just Became Berry Street's Sharpest Sales Pitch

A three-month audit window just did more for Berry Street's sales pipeline than a season of billboards could. That is the whole, unglamorous case for SOC 2 Type 2: proof outruns promise, every single time.

Quick answerSOC 2 Type 2 certification proves security controls held up over months of real operation, not just on paper. Berry Street's no-exceptions audit shows why payers, health systems and enterprise buyers now treat it as a sales requirement.
Section 01

What Berry Street's SOC 2 Type 2 Certification Actually Proves#

The fox does not brag about the burrow, it lets the tracks tell the truth. Berry Street, the nutrition-therapy platform that connects patients to registered dietitians, did something close to that on 20 August 2026, when it announced SOC 2 Type 2 certification and let a stranger's signature do the talking. Johanson Group LLP examined the Security criterion drawn from the AICPA's Trust Services Criteria over a three-month period ending June 2026, according to Berry Street's own announcement. Completed with no exceptions noted: three careful, unglamorous words that carry more weight than any headline.

Berry Street's co-founder and CEO, Noah Kotlove, framed the reasoning plainly: "Nutrition care only works when people feel safe being honest about their health." The platform already serves more than 200,000 patients through 1,250-plus insurance plans, per Berry Street's own site, which means every clean claim, every diagnosis and every lab value has somewhere private to go. Diagnoses, lab results, medication records and behavioural health detail all sit inside the protected health information that HIPAA's Privacy Rule obliges a covered entity to guard, minimum-necessary disclosure, documented access, the full administrative and technical stack. A SOC 2 Type 2 report is the paperwork that says the door actually locks.

A policy is a promise. SOC 2 Type 2 is the receipt, dated, signed and checked three months later.
folkfox, on why compliance now sells

Read as a marketing event rather than a filing cabinet update, the announcement is doing exactly what Berry Street says it is doing: opening doors to payer, health-system and enterprise partnerships that would not touch a vendor without one. That is the story folkfox keeps finding across regulated sectors, and it is why this piece treats SOC 2 Type 2 as sales enablement first and a compliance checkbox second.

Section 02

Type 1 Promises, SOC 2 Type 2 Proves#

Most buyers use the two labels loosely, and most vendors let them. A SOC 2 Type I report checks whether the right controls are designed and documented on a single day; a SOC 2 Type 2 report checks whether those same controls actually held up while nobody was watching. Imperva's own SOC 2 explainer puts it cleanly: Type I answers whether a vendor's system design is suitable, Type II details how effectively it operates in practice, typically across a run of months rather than one afternoon.

How many months varies. A-LIGN, one of the AICPA's own accredited audit firms documents Type II periods running three to twelve months, and notes that this deeper report is "increasingly what customers require." a broader survey of SOC reporting puts the typical window at nine to twelve. Berry Street's three-month period sits at the short end of that range, still a genuine observation window, not a snapshot, and still a real gap between a policy on a shelf and a practice proven in production.

soc 2 type 2 certification report examined with a magnifying glass by a fox
The clean line survives one close reading only if the evidence behind it is real.

This is the part smaller teams skip past, and it is the whole point of SOC 2 Type 2. Writing a policy takes an afternoon. Proving the policy was followed, every week, for three to twelve months, across every named control, takes a working security programme, screenshots, tickets, access logs, the unglamorous evidence trail an auditor actually samples. Microsoft's own audit documentation is instructive here: Office 365 runs a rolling twelve-month run window, refreshed with quarterly bridge letters in the gaps, because a Type 2 opinion has an expiry date the moment the observation window closes. That is the real work, and no amount of tidy policy paperwork substitutes for it.

Where SOC 2 Type 2 is turning from nice-to-have to gatekeeper
Slope chart showing illustrative SOC 2 Type 2 demand rising from 2025 to 2026 across health RFPs, enterprise SaaS and SMB buyer segments20252026Health & payer: 35 to 65Health & payer 35%65%Enterprise SaaS: 50 to 72Enterprise SaaS 50%72%Startups & SMBs: 18 to 34Startups & SMBs 18%34%
Illustrative, not measured: SOC 2 Type 2 mentions climb across every buyer segment from 2025 to 2026, steepest among health and payer RFPs, exactly the audience Berry Street named in its own announcement.

Read the slope the way you would read a fox's trail across frost: the direction matters more than the exact stride. Every buyer segment is asking earlier and asking harder, and the segment asking hardest, health and payer procurement, is precisely where Berry Street just planted its flag.

SOC 2 vs ISO 27001: attestation versus certification#

Buyers weighing SOC 2 vs ISO 27001 often assume the two are the same proof wearing different labels. They are not. SOC 2 is an audit that produces an attestation report, carried out by a licensed CPA firm; ISO 27001 is a certification, issued by an accredited ISO 27001 certification body, according to A-LIGN's own comparison of the two frameworks.

The renewal clocks differ too: a SOC 2 report, Type I or Type II, is considered valid for twelve months from its report date, while an ISO 27001 certificate runs three years, propped up by annual surveillance audits in between. Reach differs as well, SOC 2 was built by the AICPA and stays the default ask across North America, where Berry Street operates, while ISO 27001 is the standard international buyers reach for first.

Neither substitutes for the other: a payer asking for a SOC 2 Type 2 report will not accept an ISO 27001 certificate instead, and a vendor selling into both US and European enterprise procurement eventually needs both, not a choice between them.

Section 03

Why B2B Buyers Now Expect a SOC 2 Type 2 Report Before Talking Numbers#

Enterprise procurement teams stopped taking a vendor's word for its own security years ago. Imperva notes that SOC 2 has become a baseline expectation for security-conscious buyers evaluating SaaS and cloud providers, a competitive differentiator precisely because it is not legally mandated. Nobody has to ask for it. Enough buyers do anyway that not having one is its own answer. Even the hyperscalers play this game seriously: AWS's own SOC compliance FAQ issues its own SOC 2 report twice a year, and gates access behind a signed non-disclosure agreement rather than a marketing page, because the report itself is the sales asset, not the announcement about it.

Vendors have noticed. Vanta positions its own SOC 2 tooling around exactly this buyer behaviour, building a public trust page so a prospect can read the report before a sales call even starts. That is a vendor's own marketing framing, worth repeating honestly rather than as a measured benchmark: it describes an incentive, not a proven percentage.

u/VoldemortWasaGenius
I'm going for a SOC 2 type 1 report. I am using Vanta integrated with all the platforms we are using: GitHub, Linear, AWS, Fly, etc. Assuming all the policies are written and the tests are passing, is it safe to assume I'll get a clear report?
25 August 2026, r/soc2View on Reddit

That is a practitioner mid-prowl, tools connected, policies drafted, tests green, and still asking the honest question in the r/soc2 thread. The answer, gently, is that a Type I report can absolutely come back clean on exactly that evidence, because Type I only checks whether the controls are designed and documented today. A SOC 2 Type 2 report asks the harder question: did they hold, week after week, for months. Green tests on day one are the starting scent, not the finished trail.

Section 04

What Actually Blocks Small Teams From SOC 2 Type 2#

Every team that has gone through this will name the same handful of snags, and none of them are the paperwork. The paperwork is the easy part; the calendar is the hard part.

What actually blocks a small team from SOC 2 Type 2
Observation period length
steepest
Evidence collection
high
Penetration test cost
medium
Auditor scheduling
medium
Policy-practice gap
steady
Directional, not a survey measurement: the observation period itself, not the policy writing, is what practitioners and auditors describe as the steepest climb, a pattern visible in the Reddit thread above and in A-LIGN's own guidance.

Penetration testing alone is a recurring, real cost most first-time teams underbudget: it sits outside the audit fee and has its own supplier, its own scheduling and its own report to fold into the evidence pack. Auditor availability is the second quiet tax, good AICPA-accredited firms book out months ahead, so a team that starts shopping for an auditor after the observation window opens has already lost time it cannot buy back.

The gap the Reddit thread actually shows#

The practitioner-practical gap is the one worth naming out loud, because it is the one automated compliance tooling cannot close on its own. Connecting GitHub, Linear, AWS and Fly to a platform like Vanta proves the controls exist and the tests currently pass. It does not, on its own, prove three to twelve months of consistent operation, which is the entire difference between a Type I promise and a SOC 2 Type 2 proof. Small teams that budget for the calendar, not just the checklist, are the ones that clear it without a scramble.

Section 05

Turning SOC 2 Type 2 Into a Marketing Asset, Not Just a Compliance Line#

Here is where most compliance teams stop and most marketing teams should start. Berry Street did not bury its SOC 2 Type 2 news in a trust-centre footnote, it put a named auditor, a named criterion and a named CEO quote in a press release, and tied every sentence back to the partnerships it unlocks. That is content marketing done properly: specific claims, sourced facts, nothing a generative summary or a sceptical procurement officer has to take on faith.

The honest version of this pitch matters more than the polished one. Selling SOC 2 Type 2 as a vague trust signal invites the same scepticism as any other superlative; selling it as "security operated correctly for a named period, examined by a named firm, against a named criterion" is the kind of claim a buyer's own security team can verify in minutes. That distinction is brand strategy work as much as it is compliance work, and it is exactly the discipline folkfox brings to SEO and GEO for regulated clients across DORA-scoped operational resilience work and beyond.

None of this happens in isolation. CMMC's own marking mess already showed how a single missed deadline reframes an entire compliance narrative, and NIS2's referral to the Court of Justice made the same point about cross-border enforcement: the frameworks keep multiplying, and the vendors that turn each one into a plain, provable sentence are the vendors that keep closing enterprise deals while their competitors are still drafting policy. A SOC 2 Type 2 report, told honestly, is one more sentence procurement can check without picking up the phone.

The fox that survives the winter is not the boldest one, it is the one that leaves the clearest trail back to a den worth trusting. Berry Street's audit is that trail. What a growth team does with it next, plain language, sourced claims, a sentence procurement can verify, decides whether the certification becomes a sales asset or stays a filing-cabinet footnote.

Questions

Frequently asked questions#

What is SOC 2 Type 2 certification?

SOC 2 Type 2 certification is an independent auditor's opinion that a company's security controls, mapped to the AICPA's Trust Services Criteria, were not just designed correctly but actually operated effectively over a set period, usually three to twelve months. Berry Street's 2026 report covered three months and the Security criterion specifically.

What's the difference between SOC 2 Type 1 and SOC 2 Type 2?

A Type 1 report checks whether controls are designed and documented correctly on a single day. A SOC 2 Type 2 report checks whether those same controls actually worked, consistently, across an extended observation window. Type 2 is the harder, slower, more trusted of the two.

What's on a SOC 2 compliance checklist?

A practical SOC 2 compliance checklist covers scoping the trust criteria, writing and publishing policies, wiring up access controls and monitoring, running a penetration test, closing gaps found in a readiness assessment, then holding steady through the full observation period before the auditor's fieldwork begins.

How much does a SOC 2 audit cost?

SOC 2 audit cost varies with scope and company size, but the total bill is rarely just the auditor's fee. Readiness work, compliance tooling, and a separate penetration test each add their own line item, which is why teams that budget only for the audit itself are usually surprised by the real total.

Is SOC 2 the same as ISO 27001?

No. The short version of SOC 2 vs ISO 27001 is attestation versus certification: SOC 2 is an audit that produces an attestation report from a licensed CPA firm and is considered valid for twelve months, while ISO 27001 is a certification issued by an accredited certification body and stays valid for three years, with annual surveillance audits in between. SOC 2 stays the default ask across North America; ISO 27001 is the standard international buyers reach for first. The two are not interchangeable, a buyer asking for one will rarely accept the other.

Does a SOC 2 report expire?

Yes. A SOC 2 Type 2 report covers a fixed observation period, so it ages the moment that window closes. Microsoft's own Office 365 attestations run on a rolling twelve-month cycle for exactly this reason, with bridge letters covering the gap until the next full audit lands.

Keep reading

Read more on this topic#

Ready to make your SOC 2 Type 2 certification sell?

folkfox turns audited compliance into a claim buyers can verify: scoped criteria, dated evidence, and content that survives a sceptical procurement read.