Trust Services Criteria
A SOC 2 report evaluates controls against the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security, covered by the Common Criteria, is mandatory. The other four are added depending on the service and what customers need.
Type I vs Type II
A Type I report checks whether controls are suitably designed at a single point in time. A Type II report checks whether they operated effectively over an observation period, usually between three and twelve months. Customers generally expect a Type II.
Report, not certification
SOC 2 is an attestation: a licensed CPA firm issues an opinion on the organisation's controls. There is no SOC 2 certificate, and the report is normally shared with customers under a confidentiality agreement.
SOC 2 vs ISO 27001
SOC 2 is most requested by customers in the United States, while ISO 27001 is more common in Europe. The two share many controls, so companies selling internationally often work towards both.




