Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is SOC 2, and what does the report prove?

Last verified

SOC 2 is an attestation examination in which a licensed CPA firm reports an opinion on a service organisation's controls against the AICPA Trust Services Criteria. The deliverable is a report, not a certificate. Security (the common criteria) is always in scope; the other four categories are optional.

SOC 2 explained, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.

This is what SOC 2 is, not whether YOU need it

Audience: a founder, CTO, CISO, engineering lead, compliance owner, auditor, or investor meeting SOC 2 for the first time. This page explains the instrument. It does not determine that YOU need SOC 2, does not scope YOUR examination, and does not issue a SOC 2 report. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor.

SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report. Buyers ask for one in procurement and vendor-risk review, and contracts sometimes promise one. That is a commercial fact, not a legal duty, and it is why the answer to "do we need SOC 2" is a sales and contract question before it is a security one.

"SOC 2 certified" is a misnomer. There is no SOC 2 certificate, no SOC 2 certification body, and no expiry sticker: the deliverable is a practitioner's report containing an opinion, addressed to the service organisation and shared under its control. ISO/IEC 27001, by contrast, is a certifiable management-system standard where an accredited certification body issues a certificate. The two instruments are not interchangeable. Last verified 10 September 2026. Not legal advice.

  • Type I addresses the design of controls at a point in time. Type II addresses operating effectiveness over a review period. Most buyers ask for Type II.
  • The examination is performed under SSAE 18 (AT-C sections 105 and 205). Those standards bind the CPA firm, not you.
  • The subject matter is the AICPA Trust Services Criteria. That text is proprietary AICPA material: this page cites criteria series references (CC1–CC9 and the optional categories) and paraphrases their subject areas. It never reproduces the licensed criterion wording.
  • A SOC 2 report is not a security guarantee, not a penetration test, not a vulnerability scan, and not a statement that no incident will occur.

Who is who in a SOC 2 examination

Three parties matter, and conflating them is the most common early mistake. Last verified 10 September 2026.

Roles in a SOC 2 examination (descriptive paraphrase of the attestation standards; not legal advice)
PartyWhat it doesKind of textWhat it cannot do
Service organisation (you)Defines the system description and the scope, asserts that its description is fair and its controls are suitably designed (and, for Type II, operated effectively), and produces evidence.Attestation-standard requirement — the responsible party's assertion is a precondition of the examination under AT-C sections 105 and 205.Cannot issue its own opinion. A self-assessment is not a SOC 2 report.
Licensed CPA firm (the practitioner)Plans and performs the examination, tests controls, forms an opinion, and issues the report.Attestation-standard requirement — only a licensed CPA firm may perform the examination and issue the report.Cannot design or operate your controls for you and remain independent.
Compliance-automation toolingCollects, organises, and monitors evidence; tracks readiness; shortens the request-list scramble.SRM recommendation — helpful, and this product is in that category.Is not the attestor. Tooling does not issue an opinion, does not sign the report, and does not replace the CPA examination.
Report user (your buyer, their auditor, an investor)Reads the report, the opinion, the description, the tests performed, and any exceptions, and decides whether the vendor is acceptable.Market observation — how procurement commonly uses the report.Cannot treat an unqualified opinion as proof that no incident will occur.

The Trust Services Criteria — security is mandatory, the rest are choices

SOC 2 is reported against the Trust Services Criteria. Security — expressed as the common criteria, referenced as the CC series — is in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are additional categories you choose, usually because a customer contract or a regulator-adjacent commitment pushes you there. Adding categories adds criteria, evidence, testing, and cost.

The table below gives the reference and a plain-language subject area. It is paraphrase. The Trust Services Criteria are proprietary AICPA material and their licensed criterion text is never reproduced here — read it from the AICPA source. Last verified 10 September 2026. Not legal advice.

Trust Services Criteria categories by reference (paraphrase of subject areas; the criterion text is proprietary AICPA material and is not reproduced)
CategoryReference seriesSubject area (paraphrase)In every SOC 2?
SecurityCC1–CC9 (the common criteria)Governance and control environment; communication; risk assessment; monitoring; control activities; logical and physical access; system operations; change management; risk mitigation including vendors.Yes. Attestation-standard requirement in practice — the common criteria are the floor of a SOC 2 examination.
AvailabilityA seriesWhether the system is available for operation and use as committed — capacity, backup, recovery.Optional. Chosen because uptime commitments matter to the buyer.
ConfidentialityC seriesHow information designated confidential is protected through its lifecycle, including disposal.Optional. Commonly added for enterprise data-handling commitments.
Processing IntegrityPI seriesWhether processing is complete, valid, accurate, timely, and authorised.Optional. Usually relevant to transaction or payments-adjacent processing.
PrivacyP seriesHow personal information is collected, used, retained, disclosed, and disposed of against the entity's own notice.Optional. Not the same as GDPR compliance, and adding it is not a data-protection determination.

What is actually inside a SOC 2 report

A SOC 2 report is a document, and its parts do different work. Read the opinion first, then the exceptions, then the description. Market observation: many buyers read only the opinion paragraph, which is why exceptions surprise people later.

  • The independent service auditor's report — the opinion. Unmodified (often called unqualified), qualified, adverse, or a disclaimer of opinion.
  • Management's assertion — your statement about the description and the controls. Attestation-standard requirement.
  • The system description — what is in scope: services, infrastructure, software, people, procedures, data, and the boundaries you drew.
  • For Type II: the description of the auditor's tests of controls and the results, including any exceptions noted.
  • Complementary user entity controls (CUECs) and, where applicable, complementary subservice organisation controls — things the report assumes the reader or a subservice provider does. Best practice for a buyer: read these before relying on the report.
  • Other information provided by management, which is not covered by the opinion. Best practice: do not treat it as tested.

SOC 2 versus the things it is confused with

Naming a neighbouring instrument is not linking it, and it is not a determination that either applies to YOU. Last verified 10 September 2026. Not legal advice.

SOC 2 contrasted with adjacent instruments (paraphrase; not a determination that any of them applies to YOU)
InstrumentWhat it isKind of textHow it differs from SOC 2
SOC 1An examination over controls relevant to a user entity's internal control over financial reporting.Attestation-standard requirement — also SSAE 18, different subject matter.Financial-reporting focus, not the Trust Services Criteria.
SOC 3A general-use report derived from a SOC 2 examination, without the detailed description and test results.Attestation-standard requirement — issued by the same CPA firm.Publishable in marketing; too thin for a vendor-risk reviewer.
ISO/IEC 27001A certifiable information-security management-system standard. An accredited certification body issues a certificate after audit.Voluntary standard — not a statute, not an AICPA attestation.Certification with a certificate and surveillance cycle, versus a CPA firm's opinion in a report. The SOC 2 versus ISO 27001 comparison on this site walks the trade-off.
HIPAA, PCI DSSRegulatory or contractual-scheme regimes with their own enforcement paths.Legal requirement or scheme requirement where it applies — unlike SOC 2, which no statute mandates.A SOC 2 report does not discharge a HIPAA or PCI DSS obligation.
Penetration testA point-in-time technical assessment by a security testing provider.Best practice — commonly used as evidence within an examination.Not an attestation, no opinion, and not a substitute for a SOC 2 report.

Kinds of text on this page

Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.

How to read the claims on this page (not a ranking; not legal advice; last verified 10 September 2026)
Kind of textWhat it meansWhat it is not
Attestation-standard requirementSSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination.Not a statute, and it binds the practitioner rather than you.
Trust Services Criteria referenceA pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100.Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase.
Best practiceWhat experienced practitioners commonly do to be ready and to make a report readable.Not required by any attestation standard. Skipping it is not an exception.
Market observationWhat buyers, contracts, and firms are commonly observed to do.Not a rule, not a quote, and not a promise about YOUR deal, timeline, or price.
SRM recommendationSomething this product suggests doing.Not a legal requirement, not an attestation requirement, and not an audit opinion.

What to do now

This is orientation, not a project plan and not a determination that you need a report. If a buyer is already asking, the applicability and lifecycle guides on this site are the next stops.

  • Write down who is asking for SOC 2 and what they wrote in the contract or questionnaire. The demand, not the standard, sets your scope and deadline.
  • Decide Type I or Type II before pricing anything. Most buyers want Type II, and the observation period is the long pole.
  • Decide which optional categories a customer actually requires. Adding Availability, Confidentiality, Processing Integrity, or Privacy because it sounds thorough buys criteria, evidence, and cost you may not need.
  • Read the Trust Services Criteria from the AICPA source rather than a blog summary, including this one. The criterion text is what the CPA firm tests against.
  • Stop saying "SOC 2 certified" internally. The habit leaks into sales collateral and a careful buyer notices.
  • Do not engage a compliance-automation vendor believing you have engaged an auditor. Only a licensed CPA firm can perform the examination and issue the report.

Checklist

A question list for a first conversation, not an audit programme. Each item is labelled by the kind of text it comes from.

  • Do we know which buyer or contract is driving this, and by when? Market observation — no statute requires a SOC 2 report.
  • Type I or Type II, and if Type II, how long a review period? Attestation-standard requirement that Type II covers a period; the length is a scoping decision.
  • Which Trust Services Criteria categories are in scope beyond the common criteria? Trust Services Criteria reference — read TSP section 100 for the criteria themselves.
  • Have we drawn a system boundary we can actually describe: services, infrastructure, software, people, procedures, data? Attestation-standard requirement that the description be fair.
  • Do we know which subservice organisations are involved, and whether they will be carved in or carved out? Best practice to decide before fieldwork.
  • Is there a named human accountable for the examination, with time to do it? SRM recommendation.
  • Have we engaged a licensed CPA firm, and verified the licence? Attestation-standard requirement — verify with the relevant state board of accountancy.

Where this shows up in ShipReady Metrics

The bundled framework key soc2 is customer-visible. Its version label references the 2017 Trust Services Criteria with the 2022 revised points of focus. Its control-set is a starter subset — an illustrative readiness mapping to be tailored by a compliance owner, not the criteria themselves and not an audit programme. Readiness in this product is not an attestation opinion.

If you already have a session: the signed-in compliance area holds evidence collection, evidence review with the met-verdict overlay, the policies library, and a crosswalk from 24 frameworks — including SOC 2 — to this product's canonical controls. The crosswalk cites criteria series references only; it does not reproduce Trust Services Criteria text, and mapped coverage is not a count of criteria met. Connector-sourced evidence (dependency, code-scanning, and secret-scanning ingest) lands in the same place. ShipReady Passport and the auditor share token let you hand a reviewer a scoped view. The cyber risk register lives under the security area.

The obligation map lists frameworks the organisation has marked in-scope, including soc2 if that mark is set. Marking soc2 in-scope is not a determination that a buyer requires SOC 2, not a scope decision for an examination, and not a report. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.

Primary sources (last verified 10 September 2026)

Every claim about the examination on this page comes from one of these. If a later revision changes something, the date above is how you can see we have not re-checked yet.

AICPA Trust Services Criteria, TSP section 100 — 2017 Trust Services Criteria with the 2022 revised points of focus. Proprietary AICPA material: cited by reference (CC1–CC9 and the optional categories) and paraphrased, never reproduced. AICPA attestation standards SSAE 18, AT-C section 105 (concepts common to all attestation engagements) and AT-C section 205 (examination engagements). AICPA SOC 2 guidance for service organisations. AICPA Peer Review Program and the state boards of accountancy for practitioner licensing. These are not a complete list, and none of them is legal advice.

The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.

Frequently asked questions