All frameworks
Attestation reportUnited States, accepted globally

SOC 2

SOC 2 (AICPA Trust Services Criteria)

SOC 2 is an attestation report issued by a licensed CPA firm on a service organisation’s controls against the AICPA Trust Services Criteria: security (mandatory), availability, processing integrity, confidentiality and privacy. Type I reports on design at a date; Type II on operation over a period.

Who it reaches

  • SaaS and service companies selling to US enterprises, whose vendor-risk teams ask for a Type II as a matter of course.
  • Companies that hold or process customer data on behalf of others.
  • Startups whose first enterprise deal is contingent on a report.

What the audit checks

  1. 01Readiness: controls designed, documented and running; the observation period starts here.
  2. 02Type I (optional): the auditor examines control design as of a date.
  3. 03Type II: the auditor samples evidence across the observation period, usually six or twelve months, and issues the report.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Scope the criteria and systems1 to 2
Readiness and control implementation6 to 16
Observation period12 to 52
Fieldwork and report4 to 8

Evidence to have ready

  • System description and control matrix
  • Policies with owners, versions and approvals
  • Populations: changes, joiners and leavers, incidents, vendors
  • Access reviews and offboarding tickets for the period
  • Change approvals and deployment records
  • Monitoring alerts and their handling
  • Vulnerability scans and remediation tracking
  • Backup and restore test evidence
  • Vendor assessments and agreements
  • Security awareness training completions

Questions people ask

Type I or Type II first?
If a buyer needs paper now and the observation period has not run, a Type I bridges the gap. If buyers can wait, go straight to a Type II; the observation period does not shorten because a Type I was done.
Who can issue a SOC 2 report?
Only a CPA firm licensed in the United States, because SOC 2 is an attestation under AICPA standards. Firms elsewhere can perform fieldwork, but the report is signed by the CPA firm.
How long is a SOC 2 report good for?
It is dated, not expiring. Buyers usually want a report whose period ended within the last twelve months, with a bridge letter from management covering the months since.
Can my consultant also be my auditor?
No. Independence rules prevent the firm that designed your controls from attesting to them.

Go deeper