SOC 2
SOC 2 is an auditing standard that evaluates how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
SOC 2 (System and Organization Controls 2) is defined by the AICPA and is one of the most requested attestations for SaaS and cloud companies. A SOC 2 report is produced by an independent auditor and describes the controls a service organization has in place to protect customer data.
There are two report types. A SOC 2 Type I report assesses control design at a single point in time, while a SOC 2 Type II report evaluates whether those controls operated effectively over a period, typically three to twelve months.
Achieving SOC 2 readiness involves defining controls, collecting evidence that they operate as intended, and remediating gaps. Continuous evidence collection and control monitoring substantially reduce the manual effort of preparing for a Type II audit.
Related terms
- ISO 27001ISO/IEC 27001 is the international standard for information security management systems (ISMS), specifying requirements for establishing, operating, and continually improving information security.
- Evidence CollectionEvidence collection is the process of gathering proof that compliance controls are designed and operating effectively, for use in audits and attestations.
- Continuous ComplianceContinuous compliance is the practice of monitoring controls and collecting evidence on an ongoing basis, so an organization remains audit-ready at all times rather than only before an audit.
- Audit ReadinessAudit readiness is the state of having controls implemented and evidence organized so that an organization can enter a compliance audit with confidence and minimal last-minute work.