SOC 2
An attestation report, defined by the American Institute of Certified Public Accountants (AICPA), in which an independent auditor evaluates a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy.
SOC 2 examinations assess controls against the AICPA Trust Services Criteria. Security, also called the common criteria, is included in every report, while availability, processing integrity, confidentiality and privacy are added depending on the services provided. A Type 1 report evaluates whether controls are suitably designed at a point in time; a Type 2 report also tests whether they operated effectively over a period, commonly between three and twelve months.
SOC 2 is widely requested by customers of software-as-a-service, cloud and data processing providers, particularly in North America, as assurance that their data is handled securely. The report is intended for restricted use, typically shared under a non-disclosure agreement, and includes the auditor's opinion, management's description of the system, the controls tested and any exceptions found. SOC 3 is a shorter general-use report, and SOC 1 covers controls relevant to customers' financial reporting.
SOC 2 is an attestation, not a certification, and only licensed CPA firms can perform the examination. Scope is defined by the service organisation, so readers should check which systems and criteria are covered, the period examined and whether subservice organisations are carved out. Many controls overlap with ISO/IEC 27001, allowing organisations to pursue both with shared evidence.
Key points
- Issued by licensed CPA firms under AICPA attestation standards.
- Security is always in scope; four other criteria are optional.
- Type 1 covers design at a point in time; Type 2 covers operation over a period.
- An attestation report, not a certification.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- ISO/IEC 27001Cybersecurity & Compliance
- ISO/IEC 27002Cybersecurity & Compliance
- Compliance Gap AnalysisCybersecurity & Compliance
- NIST Cybersecurity Framework (CSF)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- Health Insurance Portability and Accountability Act (HIPAA)Cybersecurity & Compliance