Cybersecurity Glossary

What is SOC 2?

SOC 2 is an attestation report used mainly for service organizations. An independent CPA examines controls relevant to selected Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security is included in every SOC 2 examination; the other categories depend on scope.

A Type 1 report assesses control design at a specified date. Type 2 also assesses operating effectiveness over a period. SOC 2 is not a product certification and reports are not interchangeable: scope, system description, period, exceptions and complementary customer controls matter.

What should a customer review?

  • - Whether the report covers the service and locations actually used.
  • - Which criteria and subservice organizations are included or carved out.
  • - Auditor exceptions and management responses.
  • - Controls the customer must operate themselves.

The five Trust Services Categories

CategoryCore question
SecurityDo controls protect against unauthorized access, use and change?
AvailabilityIs the system available for operation according to its commitments?
Processing IntegrityIs processing complete, valid, accurate, timely and authorized?
ConfidentialityIs information designated as confidential appropriately protected?
PrivacyIs personal information handled according to the stated practices?

Type 1 or Type 2?

Type 1 shows whether described controls are suitably designed and implemented at a point in time. Type 2 additionally covers their operating effectiveness during the stated period and contains tests and results. Type 2 is therefore generally more useful for ongoing supplier assurance. A bridge letter may explain a timing gap but is not a substitute for appropriate current assurance.

What does a SOC 2 report not prove?

The report applies only to the described system, period and selected criteria. It does not guarantee absence of vulnerabilities or security of every product function. Carved-out subservice organizations and complementary user entity controls can leave important duties with the customer. Scope, exceptions, findings and actual use therefore need a combined review.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on SOC 2? Tell us!