Skip to content

SOC 2

Definition

A report on controls relevant to the AICPA's Trust Service Criteria. Produced under the AT-C 205 attestation standard. Covers Security (mandatory) plus any combination of Availability, Confidentiality, Processing Integrity, and Privacy selected by the service organisation.

Full form
Service Organization Control 2
Attestation standard
AT-C 205
Mandatory criterion
Security
Optional criteria
Availability, Confidentiality, Processing Integrity, Privacy

Common questions

Who decides which Trust Service Criteria beyond Security are included in a SOC 2 report?+

The service organisation being audited selects which additional criteria to include, based on what is relevant to the services it provides. A cloud storage provider might add Availability and Confidentiality, while a payments processor might add Processing Integrity.

What is the difference between SOC 2 Type I and Type II in practice?+

Type I assesses whether controls are suitably designed at a single point in time. Type II goes further, testing whether those controls actually operated effectively over an observation period, which is why Type II is generally regarded as stronger evidence for vendor risk decisions.

Is SOC 2 a certification the way ISO 27001 is?+

No. SOC 2 is an attestation report produced by an independent CPA firm describing controls and the auditor's opinion on them, not a pass or fail certificate issued by a standards body. It is shared under NDA rather than publicly listed like an ISO certification.

Related terms

Complementary User Entity Controls (CUECs)
Controls that the service organisation's system design assumes the user entity will implement. Listed in the SOC 2 report. If the user...
SOC 1 (SSAE 18)
A report on controls at a service organisation that are relevant to user entities' financial statements. Governed by Statement on Standards for...
Trust Service Criteria (TSC)
The five criteria used to evaluate controls in a SOC 2 engagement: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The criteria are...
Type I Report
An attestation report that provides an auditor's opinion on whether controls are suitably designed to meet the stated control objectives, assessed at...
Type II Report
An attestation report that provides an auditor's opinion on both the suitability of design and the operating effectiveness of controls over a...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.