SOC 2 Report
A SOC 2 report assesses a service organization's controls against the AICPA Trust Services Criteria. Unlike SOC 1, which focuses on financial reporting, SOC 2 covers operational and security controls.
- Audit & Assurance
A SOC 2 report is an attestation examination of a service organization's controls measured against the AICPA Trust Services Criteria. Unlike SOC 1, which addresses controls relevant to financial reporting, SOC 2 addresses operational and security commitments - which is why it has become the default assurance artifact requested during technology vendor procurement and enterprise security reviews.
The Trust Services Criteria comprise five categories. Security, formally the common criteria, is mandatory in every SOC 2 engagement. Availability, processing integrity, confidentiality, and privacy are optional and included based on the commitments the service organization makes to its customers. Most software companies scope Security plus Availability and Confidentiality; adding Privacy raises the bar considerably because it pulls in notice, choice, consent, and data subject rights.
As with SOC 1, Type 1 addresses design suitability at a point in time and Type 2 addresses operating effectiveness over a period, typically three to twelve months for a first examination and twelve months thereafter. The report includes management's assertion, the auditor's opinion, a system description, and the criteria mapped to controls with test procedures and results. Exceptions are disclosed with management responses.
Practically, SOC 2 readiness is where most of the effort sits: establishing an information security program, formalizing access provisioning and deprovisioning, implementing change management and vulnerability management, running vendor risk assessments, and maintaining evidence of control operation across the entire audit period. Evidence gaps early in a period cannot be remediated retroactively. CPA firms serve both as readiness advisors and, through a separate independent team, as examiners.