Information security

SOC 2 — System and Organization Controls

AICPA Trust Services Criteria United States / AICPA Current criteria and guidance must be verified with AICPA

Published Reviewed

What is SOC 2?

SOC 2 is an independent accountant’s attestation on a service organisation’s controls against selected Trust Services Criteria over a stated review period.

At a glance
JurisdictionUnited States / AICPA
AuthorityAICPA Trust Services Criteria
Current statusCurrent criteria and guidance must be verified with AICPA
Reviewed

Why it matters operationally

SOC 2 is the security question US enterprise buyers ask first: an independent CPA’s attestation that your controls are designed — and, for Type II, actually operated — against the Trust Services Criteria. Unlike a certification, the deliverable is a detailed report your customers read, exceptions included, which makes evidence hygiene throughout the observation period the real work. The calendar is unforgiving in a specific way: a Type II report covers a past window, so the report a deal needs next year has to start its observation period now.

Are you aware?

The dates that bind

3–12 months

The Type II window runs before the report exists

A Type II report attests controls over an observation period, typically six to twelve months. If a customer requires one by a date, subtract the window and the audit time — that is your real start deadline.

~12 months

Reports go stale by convention

Buyers generally treat a SOC 2 report older than twelve months as expired and expect the next period’s report or a bridge letter covering the gap — annual cadence is effectively mandatory once you start.

2022 criteria

The points of focus were revised

The AICPA’s 2022 revision of the Trust Services Criteria points of focus sharpened expectations on areas like data disposal and risk assessment — auditors map controls against the current guidance, not the one your programme was built on.

Where to start

  1. 1

    Choose criteria deliberately: Security is mandatory; add Availability, Confidentiality, Processing Integrity or Privacy only where customers actually need them.

  2. 2

    Write the system description honestly — service boundary, infrastructure, subservice organisations — because the report attests that description.

  3. 3

    Run evidence collection as an operating habit: access reviews, change tickets and monitoring artefacts dated inside the observation window.

Authority links

Read the official sources

The official text is the authority. This guide is only a short orientation for operational planning.

Common questions

Frequently asked questions

Type I or Type II — which do customers want?

Type I attests control design at a point in time; Type II attests operation over a period and is what mature buyers require. Type I is at best a stepping stone while your first Type II window runs.

How is SOC 2 different from ISO 27001?

ISO 27001 certifies a management system against a fixed standard; SOC 2 is an auditor’s attestation report on your selected controls against the Trust Services Criteria. US buyers usually want SOC 2, international ones ISO 27001 — one well-designed control set can feed both.

What happens if we have exceptions?

They are printed in the report with the auditor’s testing results. A handful of explained, remediated exceptions is normal; hiding weak areas by shrinking the system description is what sophisticated buyers actually penalise.

Side by side

Key terms in this guide

A quick self-check

Are you ready?

  • If a customer demanded a Type II report dated within the next nine months, has your observation window already started?
  • Could you produce this quarter’s access reviews and change-management evidence today, dated and complete?
  • Do your subservice organisations — cloud, payroll, support tooling — appear correctly in your system description with the carve-out or inclusive method decided?

Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.

This guide is general information about public law, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official source and seek qualified advice where needed.