GlossarySOC 2

SOC 2

Short answer

SOC 2 is an attestation report, defined by the AICPA, in which an independent CPA firm evaluates a service organisation's controls for security and, optionally, availability, processing integrity, confidentiality and privacy. It is widely requested by customers of SaaS and technology companies.

Trust Services Criteria

A SOC 2 report evaluates controls against the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security, covered by the Common Criteria, is mandatory. The other four are added depending on the service and what customers need.

Type I vs Type II

A Type I report checks whether controls are suitably designed at a single point in time. A Type II report checks whether they operated effectively over an observation period, usually between three and twelve months. Customers generally expect a Type II.

Report, not certification

SOC 2 is an attestation: a licensed CPA firm issues an opinion on the organisation's controls. There is no SOC 2 certificate, and the report is normally shared with customers under a confidentiality agreement.

SOC 2 vs ISO 27001

SOC 2 is most requested by customers in the United States, while ISO 27001 is more common in Europe. The two share many controls, so companies selling internationally often work towards both.

Related terms

Keep reading on this topic

SOC 2 Trust Services Criteria: Type I versus Type II, evidence collection, control design and what international customers typically ask for.

Go to the topic hub