Information security
SOC 2 — System and Organization Controls
Published Reviewed
What is SOC 2?
SOC 2 is an independent accountant’s attestation on a service organisation’s controls against selected Trust Services Criteria over a stated review period.
| Jurisdiction | United States / AICPA |
|---|---|
| Authority | AICPA Trust Services Criteria |
| Current status | Current criteria and guidance must be verified with AICPA |
| Reviewed |
Why it matters operationally
SOC 2 is the security question US enterprise buyers ask first: an independent CPA’s attestation that your controls are designed — and, for Type II, actually operated — against the Trust Services Criteria. Unlike a certification, the deliverable is a detailed report your customers read, exceptions included, which makes evidence hygiene throughout the observation period the real work. The calendar is unforgiving in a specific way: a Type II report covers a past window, so the report a deal needs next year has to start its observation period now.
Are you aware?
The dates that bind
The Type II window runs before the report exists
A Type II report attests controls over an observation period, typically six to twelve months. If a customer requires one by a date, subtract the window and the audit time — that is your real start deadline.
Reports go stale by convention
Buyers generally treat a SOC 2 report older than twelve months as expired and expect the next period’s report or a bridge letter covering the gap — annual cadence is effectively mandatory once you start.
The points of focus were revised
The AICPA’s 2022 revision of the Trust Services Criteria points of focus sharpened expectations on areas like data disposal and risk assessment — auditors map controls against the current guidance, not the one your programme was built on.
Where to start
- 1
Choose criteria deliberately: Security is mandatory; add Availability, Confidentiality, Processing Integrity or Privacy only where customers actually need them.
- 2
Write the system description honestly — service boundary, infrastructure, subservice organisations — because the report attests that description.
- 3
Run evidence collection as an operating habit: access reviews, change tickets and monitoring artefacts dated inside the observation window.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
Type I or Type II — which do customers want?
Type I attests control design at a point in time; Type II attests operation over a period and is what mature buyers require. Type I is at best a stepping stone while your first Type II window runs.
How is SOC 2 different from ISO 27001?
ISO 27001 certifies a management system against a fixed standard; SOC 2 is an auditor’s attestation report on your selected controls against the Trust Services Criteria. US buyers usually want SOC 2, international ones ISO 27001 — one well-designed control set can feed both.
What happens if we have exceptions?
They are printed in the report with the auditor’s testing results. A handful of explained, remediated exceptions is normal; hiding weak areas by shrinking the system description is what sophisticated buyers actually penalise.
Side by side
Compared against
Key terms in this guide
A quick self-check
Are you ready?
- If a customer demanded a Type II report dated within the next nine months, has your observation window already started?
- Could you produce this quarter’s access reviews and change-management evidence today, dated and complete?
- Do your subservice organisations — cloud, payroll, support tooling — appear correctly in your system description with the carve-out or inclusive method decided?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.