SOC 2 (System and Organisation Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates the controls of service organisations relevant to security, availability, processing integrity, confidentiality, and privacy. A SOC 2 report, issued by an independent CPA, is widely used by cloud service providers and SaaS companies to demonstrate trustworthiness to enterprise customers. Type I reports assess design at a point in time; Type II reports assess operating effectiveness over a period.

Overview

  • Cloud service providers and SaaS vendors undergo SOC 2 audits to demonstrate trustworthiness to enterprise buyers.
  • The report is produced by an independent CPA firm and delivered to the service organisation for controlled sharing.
  • The Trust Services Criteria are defined by the AICPA and align with COSO internal control frameworks.
  • SOC 2+ reports extend the base criteria with additional criteria sets (e.g., HIPAA, HITRUST).

Key Aspects

  • Scope definition: the system description specifying which services, infrastructure, and processes are in scope.
  • Control activities: technical and organisational controls mapped to each applicable Trust Services Criterion.
  • Testing: auditor tests control design (Type I) or samples evidence of control operation over the period (Type II).
  • Exceptions: deviations noted in the auditor opinion and management’s response.

Mechanisms

  • Organisations implement controls addressing Access Control, encryption, change management, and monitoring.
  • Continuous control monitoring and evidence collection systems automate evidence gathering.
  • Third-party vendors (sub-processors) are assessed for their own SOC 2 reports under supply-chain diligence.
  • Annual audit cycles maintain ongoing assurance; bridge letters cover gaps between report periods.

Applications

  • Enterprise SaaS procurement due diligence and vendor risk management.
  • Cloud Security posture validation for infrastructure providers.
  • Regulatory Compliance evidence supporting GDPR, HIPAA, and other frameworks.
  • Data Governance programmes establishing supplier accountability.
  • AI platform providers demonstrating trustworthy data handling practices.

Provenance