SOC 2 (System and Organization Controls 2)
SOC 2 is an auditing procedure developed by the AICPA that ensures service providers securely manage data to protect the interests of their organization and the privacy of their clients. It exists to provide a standardized framework for vendors to prove to their customers that they have implemented effective internal controls.
Who it applies to
- Software-as-a-Service (SaaS) providers.
- Cloud computing and infrastructure companies.
- Managed Service Providers (MSPs).
- Data centers and hosting services.
- Any organization that stores or processes sensitive customer data in the cloud.
How it works
The standard is based on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. While "Security" is a mandatory requirement for every SOC 2 report, organizations select the remaining criteria based on which ones are relevant to their specific service offerings.
An assessment results in one of two types of reports. A Type I report evaluates whether an organization's controls are designed correctly at a single point in time. A Type II report evaluates whether those controls were operated effectively over a specified period, typically six months to a year.
The process is conducted by an independent Certified Public Accountant (CPA) or a firm specializing in SOC audits. The auditor examines the organization's policies and evidence—such as logs, screenshots, and signed documents—to determine if the controls are functioning as described.
Getting started
- Define your scope by determining which Trust Services Criteria apply to your business model.
- Conduct a gap analysis to identify where current internal controls fall short of the criteria requirements.
- Implement missing technical controls (e.g., multi-factor authentication) and write necessary policies (e.g., incident response plans).
- Collect evidence of these controls in action, such as change management logs and employee onboarding records.
- Engage a licensed CPA firm to perform the audit and issue the final report.
Controls & requirements
- CC The Security criterion (Common Criteria)
- A The Availability criterion
- PI The Processing Integrity criterion
- C The Confidentiality criterion
- P The Privacy criterion
- CC6 Logical and physical access controls
- CC8 Change management
- CC3 Risk assessment
- CC7 System operations and monitoring
- CC9 Vendor and third-party risk management
- SOC 2 Type I vs Type II
Common misconceptions
- SOC 2 is often called a "certification," but it is actually an attestation report; there is no official governing body that issues a certificate of compliance.
- Some believe a Type I report is sufficient for long-term trust, whereas most enterprise customers require a Type II report to prove the controls work consistently over time.