SOC 2 is an attestation performed by an independent accounting firm against the AICPA Trust Services Criteria. Security is mandatory, and the other four criteria are included at the organization's election.

The output is a report describing the controls and the auditor's opinion, not a pass-fail certificate.

Alternative Names:

Service Organization Control 2, SOC 2 Report

Why it Matters?

SOC 2 is the default answer to a legal technology security questionnaire, and buyers frequently accept the label without reading the report. The substance is in the details: which criteria were in scope, whether it is a Type I or Type II, the observation period, and most importantly the exceptions the auditor noted. A report with material exceptions still says SOC 2 on the cover.

Frequently Confused with

Related terms

Frequently asked questions

Is SOC 2 a certification?

Is SOC 2 a certification?

No. It is an attestation report containing an auditor's opinion on described controls. There is no pass-fail certificate, which is why reading the report matters.

What should a buyer look for in the report?

What should a buyer look for in the report?

Which Trust Services Criteria were in scope, whether it is Type I or Type II, the observation period, and any exceptions or qualifications the auditor identified.