What is SOC 2? Reports, criteria and readiness explained
SOC 2 is an AICPA attestation examination in which an independent CPA reports on controls at a service organisation relevant to security, availability, processing integrity, confidentiality or privacy. It produces a restricted-use report, not a certification.
Who this is for: For teams preparing SOC 2-style evidence before committing to a formal SOC 2 timeline.
What SOC 2 covers
The examination uses the AICPA Trust Services Criteria. Security is included in every SOC 2 scope; availability, processing integrity, confidentiality and privacy are selected when relevant to the service and user needs.
- Service-organisation system description
- Trust Services Criteria
- Independent CPA examination
Type I and Type II reports
A Type I report addresses the description and design of controls as of a specified date. A Type II report also addresses operating effectiveness over a specified period. The service auditor defines the exact engagement with management.
What can be prepared now
Teams can organise the system scope, policies, access reviews, risk records, vendor reviews, change-management evidence, incident records and control-owner approvals before fieldwork.
What needs confirmation
Trust Services Criteria mapping, report type, review period and auditor expectations should be confirmed with the CPA firm before full SOC 2 support is promised.
Keep public statements precise
Fixed timelines, pass rates and audit coverage should only be discussed after the auditor scope is known.
Common questions
What is SOC 2 in simple terms?
SOC 2 is an independent CPA attestation report about controls at a service organisation relevant to security and any other selected Trust Services Criteria.
Is SOC 2 a certification?
No. SOC 2 results in an attestation report issued by an independent CPA firm; it is commonly described as an audit rather than a certification.
What is the difference between SOC 2 Type I and Type II?
Type I addresses control design as of a specified date. Type II also includes the service auditor's testing of operating effectiveness over a specified period.
Which Trust Services Criteria are used in SOC 2?
The categories are security, availability, processing integrity, confidentiality and privacy. Security is included, while the other categories are selected according to the engagement scope.
Does Trustega perform the SOC 2 examination?
No. Trustega can help organise readiness evidence and control records. A qualified independent CPA firm performs the SOC 2 examination and issues the report.
Primary sources
Related practical guides
- Audit preparation checklist: what to review first — A review-week preparation checklist for evidence freshness, owners, policies, vendors, access reviews and audit packs.
- Security questionnaire automation starts with reviewed answers — How to automate questionnaire responses from approved answers, evidence links, policy records and owner review.
- Vendor security review template — A vendor security review template for supplier intake, evidence requests, risk scoring, approval and reassessment.