Suspect a breach? Report it immediately — response within 1 hour.Report an incident

SOC 2

Service Organization Control 2 attestation, defined by the American Institute of CPAs (AICPA), covering the security, availability, processing integrity, confidentiality, and privacy trust service criteria.

Last updatedAugust 22, 2026

Who's affected

Primarily SaaS providers and service organizations whose clients — particularly North American or international enterprises — require formal assurance over the security and reliability of their operations as part of procurement or due diligence.

What the framework requires

SOC 2 is based on the AICPA's Trust Services Criteria: security (mandatory), and depending on the chosen scope, availability, processing integrity, confidentiality, and privacy. The organization must demonstrate, with supporting evidence, that internal controls covering these criteria are in place either over a defined period (Type II report) or at a specific point in time (Type I report), both produced by an independent CPA audit firm.

Compliance steps

01

Selecting the relevant Trust Services Criteria scope (security mandatory, other criteria based on client expectations)

02

Readiness assessment

03

Implementation and documentation of internal controls

04

Control observation period (for a Type II report)

05

Audit by an independent CPA firm and issuance of the report

Common mistakes

  • Aiming directly for a Type II report without a prior readiness assessment
  • Under-resourcing day-to-day control documentation
  • Confusing SOC 2 with a certification — it is an audit attestation, not a label issued by a certification body

Cross-mapping to other frameworks (UCM)

FrameworkCovered
iso-27001

Downloadable resource

Get the checklist by email.

Frequently asked questions

Is SOC 2 a legal requirement?

No, it is a voluntary process undertaken in response to client commercial requirements, mainly within the North American and international SaaS and digital services ecosystem.

What is the difference between a SOC 2 Type I and Type II report?

Type I assesses the design of controls at a point in time, while Type II assesses their operating effectiveness over an observation period (typically 3 to 12 months), making it the more commercially sought-after report.

Does SOC 2 replace ISO 27001?

No, they are complementary. ISO 27001 is a management system certification, SOC 2 is an audit attestation against trust criteria; an organization with an existing ISO 27001 ISMS has a reusable control base for SOC 2.

How long does it take to obtain a first SOC 2 Type II report?

Counting preparation, the control observation period, and the audit, a first Type II report typically takes several months, with the exact duration depending on initial maturity and the chosen observation period.