SOC 2
Also known as: Service Organization Controls 2
AICPA framework for reporting on controls relevant to security, availability, processing integrity, confidentiality, and privacy.
SOC 2 is the AICPA's reporting framework for evaluating controls at service organizations against the Trust Services Criteria (TSC), which span Security (the only mandatory category), Availability, Processing Integrity, Confidentiality, and Privacy. Reports come in two types: Type 1 attests to control design at a point in time, while Type 2 attests to operating effectiveness across a defined period (typically 6-12 months). SOC 2 emerged in 2011 alongside SOC 1 and SOC 3 as part of the AICPA's restructuring of its service-organization reporting framework, replacing the older SAS 70. Reports are conducted under SSAE 18 attestation standards by licensed CPAs and have become a near-universal contractual requirement for B2B SaaS, cloud infrastructure, managed services, and other technology service providers.
Core components
- Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy)
- Type 1 (point-in-time design) vs Type 2 (operating effectiveness over period)
- Common Criteria (mandatory) plus category-specific criteria
- Complementary user entity controls (CUECs)
- Subservice organization controls (carve-out vs inclusive)
- SSAE 18 attestation framework
Primary use case
Customer-facing assurance for service organizations (especially SaaS and cloud providers) demonstrating control effectiveness; common contractual requirement in vendor risk management.
Common criticisms
- Scope is auditor- and management-defined, allowing meaningful exclusions
- report quality and rigor vary widely across audit firms
- cost can be prohibitive for early-stage providers
- point-in-time and period-based assurance does not cover real-time control effectiveness
- criteria language allows substantial interpretation latitude
- can become a marketing artifact more than a security signal.
Lineage
- Child of
- SSAE 18
- Siblings
- ISO/IEC 27001, HITRUST CSF, SSAE 18, NIST Cybersecurity Framework
- Derived from
- SSAE 18