SOC 2 is an attestation report used mainly for service organizations. An independent CPA examines controls relevant to selected Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security is included in every SOC 2 examination; the other categories depend on scope.
A Type 1 report assesses control design at a specified date. Type 2 also assesses operating effectiveness over a period. SOC 2 is not a product certification and reports are not interchangeable: scope, system description, period, exceptions and complementary customer controls matter.
What should a customer review?
- - Whether the report covers the service and locations actually used.
- - Which criteria and subservice organizations are included or carved out.
- - Auditor exceptions and management responses.
- - Controls the customer must operate themselves.
The five Trust Services Categories
| Category | Core question |
|---|---|
| Security | Do controls protect against unauthorized access, use and change? |
| Availability | Is the system available for operation according to its commitments? |
| Processing Integrity | Is processing complete, valid, accurate, timely and authorized? |
| Confidentiality | Is information designated as confidential appropriately protected? |
| Privacy | Is personal information handled according to the stated practices? |
Type 1 or Type 2?
Type 1 shows whether described controls are suitably designed and implemented at a point in time. Type 2 additionally covers their operating effectiveness during the stated period and contains tests and results. Type 2 is therefore generally more useful for ongoing supplier assurance. A bridge letter may explain a timing gap but is not a substitute for appropriate current assurance.
What does a SOC 2 report not prove?
The report applies only to the described system, period and selected criteria. It does not guarantee absence of vulnerabilities or security of every product function. Carved-out subservice organizations and complementary user entity controls can leave important duties with the customer. Scope, exceptions, findings and actual use therefore need a combined review.
Thank you for your feedback! We will review it and optimize this content.