Glossary

SOC 2

SOC 2 is an auditing standard that evaluates how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

SOC 2 (System and Organization Controls 2) is defined by the AICPA and is one of the most requested attestations for SaaS and cloud companies. A SOC 2 report is produced by an independent auditor and describes the controls a service organization has in place to protect customer data.

There are two report types. A SOC 2 Type I report assesses control design at a single point in time, while a SOC 2 Type II report evaluates whether those controls operated effectively over a period, typically three to twelve months.

Achieving SOC 2 readiness involves defining controls, collecting evidence that they operate as intended, and remediating gaps. Continuous evidence collection and control monitoring substantially reduce the manual effort of preparing for a Type II audit.

Related terms