SOC 2 is an attestation performed by an independent accounting firm against the AICPA Trust Services Criteria. Security is mandatory, and the other four criteria are included at the organization's election.
The output is a report describing the controls and the auditor's opinion, not a pass-fail certificate.
Alternative Names:
Service Organization Control 2, SOC 2 Report
Why it Matters?
SOC 2 is the default answer to a legal technology security questionnaire, and buyers frequently accept the label without reading the report. The substance is in the details: which criteria were in scope, whether it is a Type I or Type II, the observation period, and most importantly the exceptions the auditor noted. A report with material exceptions still says SOC 2 on the cover.
Frequently Confused with
Related terms
Frequently asked questions
Is SOC 2 a certification?
What should a buyer look for in the report?





