Standards & Compliance

What is SOC 2?

Definition

SOC 2 is an AICPA auditing framework that evaluates service organizations' controls for security, availability, confidentiality, processing integrity, and privacy.

SOC 2 (Service Organization Control 2) is a reporting framework developed by the American Institute of CPAs (AICPA). It is designed for service organizations that store, process, or transmit customer data. SOC 2 audits assess controls based on five Trust Service Criteria (TSCs): security, availability, confidentiality, processing integrity, and privacy. The audit is performed by a licensed CPA firm.

The audit results in one of two report types. A Type I report evaluates whether controls were suitably designed as of a specific date. A Type II report goes further by testing the operating effectiveness of those controls over a defined period, typically 6 to 12 months. Organizations choose which TSCs to include based on their services and customer requirements. Security is mandatory in every SOC 2 engagement; the other four are optional.

SOC 2 sits within the broader AICPA Service Organization Control framework, which also includes SOC 1 (financial reporting controls) and SOC 3 (general use report). SOC 2 reports are restricted use, meaning they are shared only with customers, auditors, and regulators under nondisclosure agreements. Many cloud service providers, SaaS companies, and data centers obtain SOC 2 reports to demonstrate their security posture and compliance with industry expectations. The framework complements standards like ISO 27001 but is audit report based rather than certification based.

Key facts

  • Developed and maintained by the AICPA, not a government body.
  • Covers five Trust Service Criteria: security, availability, confidentiality, processing integrity, and privacy.
  • Type I reports assess control design at a point in time.
  • Type II reports assess operating effectiveness over a period (usually 12 months).
  • SOC 2 reports are restricted use and confidential, unlike SOC 3 which is publicly distributable.

How it works in practice

A cloud-based HR platform seeks enterprise clients that require proof of data protection. The company engages a licensed CPA firm to conduct a SOC 2 Type II audit covering security and availability. After six months of monitoring and evidence collection, the CPA issues a report stating the controls were operating effectively. The platform shares the report with prospects under NDA, enabling sales to proceed.

Related terms

SOC 1 SOC 3 SSAE 18 Trust Service Criteria ISO 27001 AICPA

References

More in Standards & Compliance

BCP 14

BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.

BCP 38

BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.

GDPR

The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.

HIPAA

HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.

IANA

IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.

ICANN

ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.

IETF

The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.

ISO 27001

ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ITU-T

ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.

PCI DSS

PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.

Who Is Online

In total there are 59 users online: 0 registered, 52 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369