SOC 2

Also known as: Service Organization Controls 2

framework · governance and compliance · regulatory-standard

AICPA framework for reporting on controls relevant to security, availability, processing integrity, confidentiality, and privacy.

SOC 2 is the AICPA's reporting framework for evaluating controls at service organizations against the Trust Services Criteria (TSC), which span Security (the only mandatory category), Availability, Processing Integrity, Confidentiality, and Privacy. Reports come in two types: Type 1 attests to control design at a point in time, while Type 2 attests to operating effectiveness across a defined period (typically 6-12 months). SOC 2 emerged in 2011 alongside SOC 1 and SOC 3 as part of the AICPA's restructuring of its service-organization reporting framework, replacing the older SAS 70. Reports are conducted under SSAE 18 attestation standards by licensed CPAs and have become a near-universal contractual requirement for B2B SaaS, cloud infrastructure, managed services, and other technology service providers.

Originators

American Institute of Certified Public Accountants (AICPA) high

Year / Decade

2011 (SOC framework introduced); Trust Services Criteria 2017 (current revision with 2022 points of focus update) high

Primary sources

AICPA (2017, updated 2022). Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, AICPA. SSAE 18: Attestation Standards: Clarification and Recodification (effective 2017) high

Core components

Primary use case

Customer-facing assurance for service organizations (especially SaaS and cloud providers) demonstrating control effectiveness; common contractual requirement in vendor risk management.

Common criticisms

Lineage

Child of
SSAE 18
Siblings
ISO/IEC 27001, HITRUST CSF, SSAE 18, NIST Cybersecurity Framework
Derived from
SSAE 18