GRC Careers

HomeResourcesSOC 2

CS-107 · Compliance & Frameworks

SOC 2

An attestation report on how a service organization protects customer data.

Executive Summary

SOC 2 is an attestation report, based on the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria, that describes how a service organization protects the data it handles for customers. An independent auditor examines the organization's controls and issues a report that customers can review instead of running their own audit. It is especially common among software, cloud, and technology vendors that hold customer data.

What It Is

SOC 2, short for System and Organization Controls 2, is a report produced by an independent certified public accounting firm that expresses an opinion on a service organization's controls. Unlike a certification with a pass or fail badge, it is an attestation: the auditor examines the controls against the Trust Services Criteria and describes what they found. The criteria cover security, and, when relevant to the service, availability, processing integrity, confidentiality, and privacy. Security is the foundational category most reports include. The organization defines the system in scope and the controls it operates, and the auditor tests whether those controls are suitably designed and, in a Type II report, whether they operated effectively over a period of time.

Why It Matters

For technology and service providers, a SOC 2 report has become a standard requirement in enterprise sales and vendor risk reviews. Rather than each customer auditing the vendor separately, the vendor commissions one independent report that many customers can rely on. A clean report shortens sales cycles and builds trust, while gaps flagged in a report can stall deals. For professionals, SOC 2 work sits at the intersection of security operations, compliance, and audit, and demand for people who can prepare for and manage these examinations is strong wherever software is sold to businesses.

How It Works

The organization first decides which Trust Services Criteria apply based on the promises it makes to customers, with security nearly always included. It defines the system boundary and the controls that meet the criteria, then operates those controls and collects evidence that they work. A Type I report evaluates whether the controls are suitably designed at a point in time. A Type II report goes further and evaluates whether the controls operated effectively over a review period, often several months to a year, which is why customers usually prefer it. An independent auditor performs the examination, tests a sample of evidence, and issues the report with an opinion. Because the report expires, organizations typically pursue a fresh Type II report each year.

Architecture Diagram

Select applicable Trust Services Criteria (security is foundational)Define system scope and controlsOperate controls and collect evidenceIndependent auditor tests the controlsSOC 2 report issued (Type I design, Type II design plus operation)
A SOC 2 report is produced when an auditor tests a service organization's controls against the Trust Services Criteria.

Visual Workflow

Decide which Trust Services Criteria apply, keeping security as the foundation.Define the system boundary and document the controls that meet the criteria.Operate the controls and collect evidence that they function as described.Engage an independent CPA firm to perform the examination.Complete a Type I report on design, then a Type II report over a review period.Remediate any findings and plan the next annual report.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

GRC platform
Maps controls to criteria and organizes evidence for the auditor
Evidence collection automation
Gathers proof of control operation across the review period
Policy management system
Maintains the policies that support many SOC 2 controls
Ticketing and access review tools
Provide records that controls such as access reviews actually ran

Industry Standards

AICPA Trust Services Criteria
The criteria a SOC 2 examination is performed against
AICPA attestation standards
The professional standards governing how the auditor performs the examination
ISO/IEC 27001
Related certification that overlaps with many SOC 2 controls

Career Relevance

SOC 2 is central work for GRC analysts, compliance analysts, security auditors, and CISOs at service and software companies, who prepare the environment, run controls, gather evidence, and manage the auditor relationship. Vendor risk and procurement teams read these reports to judge suppliers. For the privacy and AI governance professionals AI-Governance-Jobs.com serves, SOC 2 is a common lens through which customers evaluate whether a data-handling service can be trusted.

Interview Questions

Related Certifications

AICPA CPA (for the auditor role) ISC2 CISSP ISACA CISA

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Is SOC 2 a certification?

No. SOC 2 is an attestation report in which an independent auditor gives an opinion on a service organization's controls against the Trust Services Criteria. There is no simple pass or fail badge, so customers read the report and any noted exceptions.

What is the difference between SOC 2 Type I and Type II?

A Type I report evaluates whether controls are suitably designed at a point in time. A Type II report also tests whether those controls operated effectively over a review period, which is why customers usually consider it stronger evidence.

How is SOC 2 different from ISO/IEC 27001?

SOC 2 is a report produced by a CPA firm attesting to controls against the Trust Services Criteria, and it is common in North American technology sales. ISO/IEC 27001 is an internationally recognized certification of an information security management system. The two overlap and organizations sometimes pursue both.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

AICPA CPA (for the auditor role)ISC2 CISSPISACA CISA

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: SOC 2
  3. Go deeper: ISO/IEC 27001
  4. Go deeper: NIST Cybersecurity Framework (CSF)
  5. Validate it: work toward AICPA CPA (for the auditor role)
  6. Find the role: browse current openings

Related sheets

More in Compliance & Frameworks

Share this LinkedIn Facebook X Email