SOC 2 (System and Organization Controls 2) is an attestation report in which an independent CPA firm gives its opinion on a service organization’s controls over the systems it uses to serve customers, measured against Trust Services Criteria published by the American Institute of Certified Public Accountants (AICPA). Security is always included; availability, processing integrity, confidentiality and privacy are added if the provider selects them. A Type I report covers the design of controls at a point in time, and a Type II report covers their design and operating effectiveness over a period. For a buyer of SaaS, cloud, managed or outsourced services, it is one of the main pieces of independent evidence about a vendor’s controls, but it is not an overall security rating: what it tells you depends on its scope, the criteria selected and the complementary user entity controls the provider expects you to run.
Not to be confused with a security operations center (SOC), the team that monitors systems for threats and responds to them.
At a glance
- SOC 2 is an attestation report by a CPA firm, not a certificate; it can contain exceptions and qualifications.
- Security is always in scope; availability, processing integrity, confidentiality and privacy are added at the provider’s choice.
- A Type I report covers control design at a point in time; a Type II report covers design and operating effectiveness over a period.
- The provider decides which services, systems and locations the report covers, so scope is the first thing to check.
- It is not an overall security rating: scope, selected criteria, exceptions and the controls you are expected to run (complementary user entity controls) all decide what it means for you.
What problem it solves
Every business that hands data or operations to a provider needs some assurance that the provider protects them. Without a common format, each customer sends its own questionnaire, each provider answers hundreds of them, and nobody independently checks the answers.
SOC 2 replaces much of that with one report, examined by an outside auditor, that customers can read (usually under a nondisclosure agreement) and their own auditors can rely on. Providers use it to shorten sales cycles; buyers use it to assess vendor risk without auditing each vendor themselves. It is common in North America and increasingly requested elsewhere, often alongside ISO/IEC 27001.
How it works
Scope and criteria. The provider defines the system being examined, such as a specific product, the infrastructure it runs on and the teams that operate it, and chooses which trust services criteria to include. Security is mandatory; the others are added when they matter to customers.
Controls. The provider documents controls that meet those criteria: access management, change management, encryption, monitoring, incident response, vendor management, backup and more. Many providers prepare with a readiness assessment and compliance automation tools before the formal examination.
Examination. A licensed CPA firm tests the controls. For a Type I report it checks that they are suitably designed as of a date. For a Type II report it also tests samples of evidence across a review period to see whether they operated effectively.
The report. The result includes the auditor’s opinion, management’s description of the system, the controls and tests, and any exceptions found. Two sections deserve attention from buyers: complementary user entity controls, which are the things the provider expects you to do, and subservice organizations, such as the provider’s own cloud host, which may be excluded from the examination.
Report types
SOC 2 is one of a family of System and Organization Controls reports defined by the AICPA. There are no levels to achieve; what differs is the subject of the report, who may read it and how much detail it contains. Each is issued by an independent CPA firm, and the provider chooses which to commission.
| Report | What it covers | Who it is for | What a buyer typically receives |
|---|---|---|---|
| SOC 1 | Controls at a service provider that can affect its customers’ financial reporting, such as payroll or billing processing | Customers and their financial auditors | Full report, usually under a nondisclosure agreement |
| SOC 2 | Controls over the service against the selected trust services criteria (security, plus any of availability, processing integrity, confidentiality and privacy) | Customers, prospects and others with enough knowledge to use it, as the report specifies | Full report with system description, tests and exceptions, usually under a nondisclosure agreement |
| SOC 3 | The same criteria as SOC 2, without the detailed description of tests and results | General use; it can be shared freely | A short report, often posted on a provider’s trust page |
Both SOC 1 and SOC 2 come in two types:
| Type | What the auditor examines | How much weight buyers usually give it |
|---|---|---|
| Type I | Whether controls are suitably designed and in place as of one date | Useful for a first report or a new service; says little about how controls run day to day |
| Type II | Design plus operating effectiveness, tested with samples across a review period | The version most buyers and their auditors ask for |
The AICPA also defines related examinations, such as SOC for Cybersecurity and SOC for Supply Chain, that some organizations commission for other audiences. If a vendor offers only a SOC 3, ask whether the full SOC 2 is available under a nondisclosure agreement; this is an overview, and your own auditors or counsel can say which report your obligations call for.
When it matters for buyers
- When onboarding a vendor that will hold your data. Request the current report early, before legal and procurement negotiations harden.
- When your own customers ask you for one. If you provide services, a SOC 2 report can answer many security questionnaires at once.
- When preparing for investment, acquisition or an IPO. Due diligence teams often ask for evidence of mature controls.
- When renewing contracts. Check that the report is current and the scope still matches what you use.
Our governance, risk and compliance overview covers advisors and platforms that help with readiness and vendor reviews.
Questions to ask vendors
- Is your report Type I or Type II, and what period does it cover?
- If we rely on you for billing, payroll or other financial processing, do you also have a SOC 1?
- Which products, systems and locations are in scope, and is the service we are buying among them?
- Which trust services criteria are included beyond security?
- Were there exceptions or a qualified opinion, and how have they been fixed?
- Which subservice organizations are carved out, and where can we see their reports?
- What complementary user entity controls do you expect us to operate?
- If the period ended several months ago, can you provide a bridge letter?
How it differs from ISO/IEC 27001
ISO/IEC 27001 is an international standard for running an information security management system. An organization that meets it can be certified by an accredited certification body, and the result is a certificate with a defined scope. SOC 2 is an attestation report on specific controls, with detailed test results, issued by a CPA firm under AICPA standards. ISO/IEC 27001 shows that a management system is in place and maintained; a SOC 2 Type II report shows in detail how specific controls performed over a period. Many providers hold both. Neither is a specialized standard like PCI DSS for card data, and both feed the broader data security compliance and governance, risk and compliance (GRC) picture.
