International · American Institute of Certified Public Accountants

SOC 2, Service Organization Control 2

An attestation report on controls relevant to security, availability, processing integrity, confidentiality and privacy, prepared by an independent CPA firm.

Who it applies to

Technology and service providers whose customers need assurance about the controls protecting data those customers entrust to them. It is the report most commonly requested by buyers in the United States.

What it requires

  • Selection of the Trust Services Criteria in scope, with security always included
  • Control design that addresses each criterion, described in a system description
  • For a Type II report, evidence that controls operated effectively across a defined observation period
  • Independent examination by a CPA firm, which issues the opinion

What preparing for it involves

SOC 2 is an attestation rather than a certification, and the distinction matters commercially. A Type I report addresses control design at a point in time, and a Type II report addresses operating effectiveness across a period, usually between three and twelve months. Because a Type II tests a period, preparation is dominated by evidence discipline: the controls must be running, and their operation must be demonstrable for every month of the window.

How it concludes

A report containing the opinion of an independent CPA firm. It is restricted-use and is shared under agreement rather than published. The opinion is the auditor's, not ours.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.