Auditen
Home / Frameworks / SOC 2

SOC 2 (System and Organization Controls 2)

SOC 2 is an auditing procedure developed by the AICPA that ensures service providers securely manage data to protect the interests of their organization and the privacy of their clients. It exists to provide a standardized framework for vendors to prove to their customers that they have implemented effective internal controls.

Who it applies to

  • Software-as-a-Service (SaaS) providers.
  • Cloud computing and infrastructure companies.
  • Managed Service Providers (MSPs).
  • Data centers and hosting services.
  • Any organization that stores or processes sensitive customer data in the cloud.

How it works

The standard is based on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. While "Security" is a mandatory requirement for every SOC 2 report, organizations select the remaining criteria based on which ones are relevant to their specific service offerings.

An assessment results in one of two types of reports. A Type I report evaluates whether an organization's controls are designed correctly at a single point in time. A Type II report evaluates whether those controls were operated effectively over a specified period, typically six months to a year.

The process is conducted by an independent Certified Public Accountant (CPA) or a firm specializing in SOC audits. The auditor examines the organization's policies and evidence—such as logs, screenshots, and signed documents—to determine if the controls are functioning as described.

Getting started

  1. Define your scope by determining which Trust Services Criteria apply to your business model.
  2. Conduct a gap analysis to identify where current internal controls fall short of the criteria requirements.
  3. Implement missing technical controls (e.g., multi-factor authentication) and write necessary policies (e.g., incident response plans).
  4. Collect evidence of these controls in action, such as change management logs and employee onboarding records.
  5. Engage a licensed CPA firm to perform the audit and issue the final report.

Controls & requirements

Common misconceptions

  • SOC 2 is often called a "certification," but it is actually an attestation report; there is no official governing body that issues a certificate of compliance.
  • Some believe a Type I report is sufficient for long-term trust, whereas most enterprise customers require a Type II report to prove the controls work consistently over time.