home / guides / soc-2

Sector and contracting · AICPA

SOC 2 reports

An independent auditor report on a service organization’s controls, often requested by customers.

Who this applies to

Software and service providers that store or process customer data.

What to know

  • A SOC 2 report is issued by a licensed CPA firm against the AICPA Trust Services Criteria, with security as the base and availability, confidentiality, processing integrity, and privacy as options.
  • A Type 1 report describes controls at a point in time. A Type 2 report tests whether they operated over a period.
  • It is an attestation about your controls, not a certification, and the report is shared under an NDA.

What to do

  • Choose the criteria your customers actually ask about, and no more.
  • Collect evidence continuously, because a Type 2 audit looks back over months.