Attestation reportUnited States, accepted globally
SOC 2
SOC 2 (AICPA Trust Services Criteria)
SOC 2 is an attestation report issued by a licensed CPA firm on a service organisation’s controls against the AICPA Trust Services Criteria: security (mandatory), availability, processing integrity, confidentiality and privacy. Type I reports on design at a date; Type II on operation over a period.
Who it reaches
- SaaS and service companies selling to US enterprises, whose vendor-risk teams ask for a Type II as a matter of course.
- Companies that hold or process customer data on behalf of others.
- Startups whose first enterprise deal is contingent on a report.
What the audit checks
- 01Readiness: controls designed, documented and running; the observation period starts here.
- 02Type I (optional): the auditor examines control design as of a date.
- 03Type II: the auditor samples evidence across the observation period, usually six or twelve months, and issues the report.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Scope the criteria and systems | 1 to 2 |
| Readiness and control implementation | 6 to 16 |
| Observation period | 12 to 52 |
| Fieldwork and report | 4 to 8 |
Evidence to have ready
- System description and control matrix
- Policies with owners, versions and approvals
- Populations: changes, joiners and leavers, incidents, vendors
- Access reviews and offboarding tickets for the period
- Change approvals and deployment records
- Monitoring alerts and their handling
- Vulnerability scans and remediation tracking
- Backup and restore test evidence
- Vendor assessments and agreements
- Security awareness training completions
Questions people ask
- Type I or Type II first?
- If a buyer needs paper now and the observation period has not run, a Type I bridges the gap. If buyers can wait, go straight to a Type II; the observation period does not shorten because a Type I was done.
- Who can issue a SOC 2 report?
- Only a CPA firm licensed in the United States, because SOC 2 is an attestation under AICPA standards. Firms elsewhere can perform fieldwork, but the report is signed by the CPA firm.
- How long is a SOC 2 report good for?
- It is dated, not expiring. Buyers usually want a report whose period ended within the last twelve months, with a bridge letter from management covering the months since.
- Can my consultant also be my auditor?
- No. Independence rules prevent the firm that designed your controls from attesting to them.