Skip to main content

SOC 2.

SOC 2 is the AICPA attestation report on a service organisation's controls covering five trust criteria (security, availability, processing integrity, confidentiality, privacy). North-American canonical for SaaS vendors; ISO 27001 is the European equivalent. Type I = point-in-time; Type II = operating effectiveness over 6–12 months. Often demanded by enterprise procurement.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyAudit & complianceAll entries

The Cyber Academy take

SOC 2 is the AICPA attestation report on a service organisation's controls covering five trust criteria (security, availability, processing integrity, confidentiality, privacy). North-American canonical for SaaS vendors; ISO 27001 is the European equivalent. Type I = point-in-time; Type II = operating effectiveness over 6–12 months. Often demanded by enterprise procurement.

What SOC 2 actually attests

SOC 2 is not a certification you pass or fail. It is an attestation report produced by a licensed CPA firm under the AICPA attestation standards, in which an independent auditor expresses an opinion on whether a service organisation’s controls are suitably designed and, for Type II, operating effectively over a period. The scope is built around the Trust Services Criteria: security (the only mandatory category, also called the common criteria), availability, processing integrity, confidentiality, and privacy. You choose which of the five apply to the service you offer, and the report is sized to that choice.

Because it is an opinion on a description that management writes, two SOC 2 reports are rarely identical. One vendor may scope only security; another may add availability and confidentiality. Reading the report means reading the system description, the criteria in scope, the tests performed, and crucially any exceptions the auditor noted. A clean report with a tight scope can be weaker evidence than a report with minor exceptions across a broad scope.

Type I versus Type II

The distinction practitioners care about most is Type I versus Type II. Type I is a snapshot: the auditor opines that controls are suitably designed as of a single date. It proves the controls exist on paper and were in place that day. Type II is the one enterprise buyers actually want, because the auditor tests whether those controls operated effectively across a review period that typically spans six to twelve months, sampling evidence throughout. A Type II answers the real procurement question: did the vendor do this consistently, not just on audit day.

SOC 2 Type I vs Type II
DimensionType IType II
What is testedDesign of controlsDesign and operating effectiveness
Time frameA single point in timeA review period (commonly 6 to 12 months)
EvidenceControls in place on the dateSampled evidence across the period
Typical useFirst report, early-stage vendorsWhat enterprise procurement expects

SOC 2 next to ISO 27001

SOC 2 and ISO 27001 answer the same buyer concern from two traditions. SOC 2 is the North American canonical signal, an auditor’s attestation tied to the Trust Services Criteria and renewed on a recurring period. ISO 27001 is the international, certifiable standard built around a management system (the ISMS), with certification issued by an accredited body and maintained through surveillance audits. SOC 2 reports on controls against criteria; ISO 27001 certifies that you run a functioning system with a Statement of Applicability and continual improvement. Many vendors selling on both sides of the Atlantic end up holding both, and the control evidence overlaps heavily even though the deliverables differ.

In practice, GRC teams treat the two as complementary rather than competing. The same access controls, change management, vulnerability handling, and incident response feed both an ISO 27001 Annex A control set and the SOC 2 common criteria. The work is in mapping once and presenting twice.

Frequently asked questions

01Is SOC 2 a certification?

No. SOC 2 is an attestation report with an auditor’s opinion, not a pass/fail certificate. There is no certificate to display; what exists is a report a CPA firm issues, which you share under NDA with customers and prospects.

02Should we get Type I or Type II?

Type I is a reasonable first step to prove your controls are designed correctly, and it can be issued faster. Most enterprise buyers ultimately expect Type II because it demonstrates the controls operated effectively over a sustained period.

03Do we need all five Trust Services Criteria?

No. Security (the common criteria) is the only mandatory category. You add availability, processing integrity, confidentiality, or privacy based on the commitments you make to customers and the nature of your service.

04How does SOC 2 relate to ISO 27001?

They serve the same trust purpose through different mechanisms. SOC 2 is a US-centric attestation against the Trust Services Criteria; ISO 27001 is an international certification of an information security management system. The underlying controls overlap substantially, so evidence gathered for one largely supports the other.

05How often is a SOC 2 report renewed?

SOC 2 Type II reports cover a defined review period and are typically refreshed on a recurring cycle so customers always have current coverage. Vendors plan the audit period so there is no gap between consecutive reports.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.