Who this applies to
Software and service providers that store or process customer data.
What to know
- A SOC 2 report is issued by a licensed CPA firm against the AICPA Trust Services Criteria, with security as the base and availability, confidentiality, processing integrity, and privacy as options.
- A Type 1 report describes controls at a point in time. A Type 2 report tests whether they operated over a period.
- It is an attestation about your controls, not a certification, and the report is shared under an NDA.
What to do
- Choose the criteria your customers actually ask about, and no more.
- Collect evidence continuously, because a Type 2 audit looks back over months.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.