Auditen
Home / Glossary / SOC 2 Type II

SOC 2 Type II

Also known as: SOC 2 Type II Audit, Service Organization Control 2 (Type II)

A SOC 2 Type II report is an independent auditor's assessment of a service organization's controls over a specific period, typically six to twelve months. While a Type I report evaluates the design of controls at a single point in time, a Type II confirms that those controls operated effectively and consistently throughout the entire testing window. The audit measures performance against one or more Trust Services Criteria (TSC), such as Security, Availability, and Confidentiality.

In practice

An auditor verifies "operating effectiveness" by sampling evidence across the review period, such as requesting proof that every new employee was background-checked during the last six months rather than just checking a single recent example. The resulting report provides stakeholders with documented assurance that security policies are actually followed in daily operations.

More terms