Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is SOC 2, and what does the report prove?
Last verifiedSOC 2 is an attestation examination in which a licensed CPA firm reports an opinion on a service organisation's controls against the AICPA Trust Services Criteria. The deliverable is a report, not a certificate. Security (the common criteria) is always in scope; the other four categories are optional.
SOC 2 explained, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
This is what SOC 2 is, not whether YOU need it
Audience: a founder, CTO, CISO, engineering lead, compliance owner, auditor, or investor meeting SOC 2 for the first time. This page explains the instrument. It does not determine that YOU need SOC 2, does not scope YOUR examination, and does not issue a SOC 2 report. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor.
SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report. Buyers ask for one in procurement and vendor-risk review, and contracts sometimes promise one. That is a commercial fact, not a legal duty, and it is why the answer to "do we need SOC 2" is a sales and contract question before it is a security one.
"SOC 2 certified" is a misnomer. There is no SOC 2 certificate, no SOC 2 certification body, and no expiry sticker: the deliverable is a practitioner's report containing an opinion, addressed to the service organisation and shared under its control. ISO/IEC 27001, by contrast, is a certifiable management-system standard where an accredited certification body issues a certificate. The two instruments are not interchangeable. Last verified 10 September 2026. Not legal advice.
- Type I addresses the design of controls at a point in time. Type II addresses operating effectiveness over a review period. Most buyers ask for Type II.
- The examination is performed under SSAE 18 (AT-C sections 105 and 205). Those standards bind the CPA firm, not you.
- The subject matter is the AICPA Trust Services Criteria. That text is proprietary AICPA material: this page cites criteria series references (CC1–CC9 and the optional categories) and paraphrases their subject areas. It never reproduces the licensed criterion wording.
- A SOC 2 report is not a security guarantee, not a penetration test, not a vulnerability scan, and not a statement that no incident will occur.
Who is who in a SOC 2 examination
Three parties matter, and conflating them is the most common early mistake. Last verified 10 September 2026.
| Party | What it does | Kind of text | What it cannot do |
|---|---|---|---|
| Service organisation (you) | Defines the system description and the scope, asserts that its description is fair and its controls are suitably designed (and, for Type II, operated effectively), and produces evidence. | Attestation-standard requirement — the responsible party's assertion is a precondition of the examination under AT-C sections 105 and 205. | Cannot issue its own opinion. A self-assessment is not a SOC 2 report. |
| Licensed CPA firm (the practitioner) | Plans and performs the examination, tests controls, forms an opinion, and issues the report. | Attestation-standard requirement — only a licensed CPA firm may perform the examination and issue the report. | Cannot design or operate your controls for you and remain independent. |
| Compliance-automation tooling | Collects, organises, and monitors evidence; tracks readiness; shortens the request-list scramble. | SRM recommendation — helpful, and this product is in that category. | Is not the attestor. Tooling does not issue an opinion, does not sign the report, and does not replace the CPA examination. |
| Report user (your buyer, their auditor, an investor) | Reads the report, the opinion, the description, the tests performed, and any exceptions, and decides whether the vendor is acceptable. | Market observation — how procurement commonly uses the report. | Cannot treat an unqualified opinion as proof that no incident will occur. |
The Trust Services Criteria — security is mandatory, the rest are choices
SOC 2 is reported against the Trust Services Criteria. Security — expressed as the common criteria, referenced as the CC series — is in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are additional categories you choose, usually because a customer contract or a regulator-adjacent commitment pushes you there. Adding categories adds criteria, evidence, testing, and cost.
The table below gives the reference and a plain-language subject area. It is paraphrase. The Trust Services Criteria are proprietary AICPA material and their licensed criterion text is never reproduced here — read it from the AICPA source. Last verified 10 September 2026. Not legal advice.
| Category | Reference series | Subject area (paraphrase) | In every SOC 2? |
|---|---|---|---|
| Security | CC1–CC9 (the common criteria) | Governance and control environment; communication; risk assessment; monitoring; control activities; logical and physical access; system operations; change management; risk mitigation including vendors. | Yes. Attestation-standard requirement in practice — the common criteria are the floor of a SOC 2 examination. |
| Availability | A series | Whether the system is available for operation and use as committed — capacity, backup, recovery. | Optional. Chosen because uptime commitments matter to the buyer. |
| Confidentiality | C series | How information designated confidential is protected through its lifecycle, including disposal. | Optional. Commonly added for enterprise data-handling commitments. |
| Processing Integrity | PI series | Whether processing is complete, valid, accurate, timely, and authorised. | Optional. Usually relevant to transaction or payments-adjacent processing. |
| Privacy | P series | How personal information is collected, used, retained, disclosed, and disposed of against the entity's own notice. | Optional. Not the same as GDPR compliance, and adding it is not a data-protection determination. |
What is actually inside a SOC 2 report
A SOC 2 report is a document, and its parts do different work. Read the opinion first, then the exceptions, then the description. Market observation: many buyers read only the opinion paragraph, which is why exceptions surprise people later.
- The independent service auditor's report — the opinion. Unmodified (often called unqualified), qualified, adverse, or a disclaimer of opinion.
- Management's assertion — your statement about the description and the controls. Attestation-standard requirement.
- The system description — what is in scope: services, infrastructure, software, people, procedures, data, and the boundaries you drew.
- For Type II: the description of the auditor's tests of controls and the results, including any exceptions noted.
- Complementary user entity controls (CUECs) and, where applicable, complementary subservice organisation controls — things the report assumes the reader or a subservice provider does. Best practice for a buyer: read these before relying on the report.
- Other information provided by management, which is not covered by the opinion. Best practice: do not treat it as tested.
SOC 2 versus the things it is confused with
Naming a neighbouring instrument is not linking it, and it is not a determination that either applies to YOU. Last verified 10 September 2026. Not legal advice.
| Instrument | What it is | Kind of text | How it differs from SOC 2 |
|---|---|---|---|
| SOC 1 | An examination over controls relevant to a user entity's internal control over financial reporting. | Attestation-standard requirement — also SSAE 18, different subject matter. | Financial-reporting focus, not the Trust Services Criteria. |
| SOC 3 | A general-use report derived from a SOC 2 examination, without the detailed description and test results. | Attestation-standard requirement — issued by the same CPA firm. | Publishable in marketing; too thin for a vendor-risk reviewer. |
| ISO/IEC 27001 | A certifiable information-security management-system standard. An accredited certification body issues a certificate after audit. | Voluntary standard — not a statute, not an AICPA attestation. | Certification with a certificate and surveillance cycle, versus a CPA firm's opinion in a report. The SOC 2 versus ISO 27001 comparison on this site walks the trade-off. |
| HIPAA, PCI DSS | Regulatory or contractual-scheme regimes with their own enforcement paths. | Legal requirement or scheme requirement where it applies — unlike SOC 2, which no statute mandates. | A SOC 2 report does not discharge a HIPAA or PCI DSS obligation. |
| Penetration test | A point-in-time technical assessment by a security testing provider. | Best practice — commonly used as evidence within an examination. | Not an attestation, no opinion, and not a substitute for a SOC 2 report. |
Kinds of text on this page
Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination. | Not a statute, and it binds the practitioner rather than you. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | What experienced practitioners commonly do to be ready and to make a report readable. | Not required by any attestation standard. Skipping it is not an exception. |
| Market observation | What buyers, contracts, and firms are commonly observed to do. | Not a rule, not a quote, and not a promise about YOUR deal, timeline, or price. |
| SRM recommendation | Something this product suggests doing. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
This is orientation, not a project plan and not a determination that you need a report. If a buyer is already asking, the applicability and lifecycle guides on this site are the next stops.
- Write down who is asking for SOC 2 and what they wrote in the contract or questionnaire. The demand, not the standard, sets your scope and deadline.
- Decide Type I or Type II before pricing anything. Most buyers want Type II, and the observation period is the long pole.
- Decide which optional categories a customer actually requires. Adding Availability, Confidentiality, Processing Integrity, or Privacy because it sounds thorough buys criteria, evidence, and cost you may not need.
- Read the Trust Services Criteria from the AICPA source rather than a blog summary, including this one. The criterion text is what the CPA firm tests against.
- Stop saying "SOC 2 certified" internally. The habit leaks into sales collateral and a careful buyer notices.
- Do not engage a compliance-automation vendor believing you have engaged an auditor. Only a licensed CPA firm can perform the examination and issue the report.
Checklist
A question list for a first conversation, not an audit programme. Each item is labelled by the kind of text it comes from.
- Do we know which buyer or contract is driving this, and by when? Market observation — no statute requires a SOC 2 report.
- Type I or Type II, and if Type II, how long a review period? Attestation-standard requirement that Type II covers a period; the length is a scoping decision.
- Which Trust Services Criteria categories are in scope beyond the common criteria? Trust Services Criteria reference — read TSP section 100 for the criteria themselves.
- Have we drawn a system boundary we can actually describe: services, infrastructure, software, people, procedures, data? Attestation-standard requirement that the description be fair.
- Do we know which subservice organisations are involved, and whether they will be carved in or carved out? Best practice to decide before fieldwork.
- Is there a named human accountable for the examination, with time to do it? SRM recommendation.
- Have we engaged a licensed CPA firm, and verified the licence? Attestation-standard requirement — verify with the relevant state board of accountancy.
Where this shows up in ShipReady Metrics
The bundled framework key soc2 is customer-visible. Its version label references the 2017 Trust Services Criteria with the 2022 revised points of focus. Its control-set is a starter subset — an illustrative readiness mapping to be tailored by a compliance owner, not the criteria themselves and not an audit programme. Readiness in this product is not an attestation opinion.
If you already have a session: the signed-in compliance area holds evidence collection, evidence review with the met-verdict overlay, the policies library, and a crosswalk from 24 frameworks — including SOC 2 — to this product's canonical controls. The crosswalk cites criteria series references only; it does not reproduce Trust Services Criteria text, and mapped coverage is not a count of criteria met. Connector-sourced evidence (dependency, code-scanning, and secret-scanning ingest) lands in the same place. ShipReady Passport and the auditor share token let you hand a reviewer a scoped view. The cyber risk register lives under the security area.
The obligation map lists frameworks the organisation has marked in-scope, including soc2 if that mark is set. Marking soc2 in-scope is not a determination that a buyer requires SOC 2, not a scope decision for an examination, and not a report. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
Every claim about the examination on this page comes from one of these. If a later revision changes something, the date above is how you can see we have not re-checked yet.
AICPA Trust Services Criteria, TSP section 100 — 2017 Trust Services Criteria with the 2022 revised points of focus. Proprietary AICPA material: cited by reference (CC1–CC9 and the optional categories) and paraphrased, never reproduced. AICPA attestation standards SSAE 18, AT-C section 105 (concepts common to all attestation engagements) and AT-C section 205 (examination engagements). AICPA SOC 2 guidance for service organisations. AICPA Peer Review Program and the state boards of accountancy for practitioner licensing. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.