SOC 2 Compliance
SOC 2 is an AICPA attestation report on how a service organization controls security, and optionally availability, processing integrity, confidentiality, or privacy. A licensed CPA firm examines your system description and controls and issues a Type 1 (design as of a date) or Type 2 (design plus operating effectiveness over a period) report. It is not a certification.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — SOC 2 Compliance
SOC 2 is the report a licensed CPA firm writes after examining how a service organization controls security (and maybe a few friends: availability, processing integrity, confidentiality, privacy). It is an attestation with an opinion. It is not a certificate, a badge, or a spell that makes breaches impossible.
People used to lean on a single old service-auditor standard for almost everything. The modern split is clearer: SOC 1 when the story is financial reporting controls, SOC 2 when the story is Trust Services detail for customers and risk teams, SOC 3 when you want the same Trust Services idea in a shorter public-facing shape.
Two ideas do most of the carrying. First, the Trust Services Criteria: Security is always in; the other categories join when your commitments make them relevant. Second, Type 1 versus Type 2: Type 1 asks whether the description and design look right as of a date; Type 2 asks whether the controls actually operated across a period and shows the auditor's tests. Enterprise procurement almost always wants Type 2.
The surprise is that the system description and the observation period matter as much as the control list. Carve-outs, subservice cloud providers, and CUECs (the controls your customers must run) decide what the opinion really covers. A six-month Type 2 window that starts before reviews and logging are stable is how you buy exceptions in bulk.
Automation platforms can collect evidence. Only the CPA issues the opinion. A green dashboard is a helpful roommate; it is not the report.
Read the Intro for the full map. Keep the Cheatsheet open when scoping categories and report type. Use the Practice Reference when you map controls and dry-run evidence retrieval. Field Notes is where the costly timing and scope mistakes live. The Exercise is a fictional SaaS scoping drill if you want to practice before a real kickoff.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/
Supports
- SOC 2 definition as examination of controls relevant to Trust Services Categories
- Intended users needing detailed assurance about security and related categories
- Links to TSC and description criteria resources
- Quiz answers on SOC 2 purpose, Type distinctions, and suite placement
- Field Notes shift card on AICPA scrutiny of rushed SOC engagements and tool arrangements
- https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
Supports
- 2017 Trust Services Criteria with 2022 revised points of focus
- Categories Security, Availability, Processing Integrity, Confidentiality, Privacy
- Criteria use in attestation and consulting engagements on systems and information
- Timeline events for 2017 TSC and 2022 points of focus
- Quiz answers on Security baseline and points of focus
- https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1
Supports
- SOC 1 focus on controls relevant to user entities' ICFR
- Intended users are user entities and user auditors
- Quiz answer distinguishing SOC 1 from SOC 2
- https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-3
Supports
- SOC 3 addresses same Trust Services Categories as SOC 2 with less detail
- General-use distribution contrast with SOC 2
- Quiz answers on SOC 3 pairing with SOC 2
- https://www.aicpa-cima.com/cpe-learning/publication/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy
Supports
- Authoritative guide for SOC 2 and SOC 3 examination and reporting
- Application of 2017 TSC with 2022 points of focus and 2018 description criteria
- Timeline support for description criteria publication lineage
- https://www.aicpa-cima.com/resources/download/get-description-criteria-for-your-organizations-soc-2-r-report
Supports
- 2018 SOC 2 Description Criteria with revised implementation guidance 2022
- Benchmarks for preparing and evaluating management's system description
- Learner reference rationale for description criteria link
- http://assets.ctfassets.net/rb9cdnjh59cm/26JcnLaBPeUZzSZOa3jwpx/5cf69b978c04ce04cd21c488a6899753/ssae-18.pdf
Supports
- SSAE 18 clarification and recodification into AT-C sections
- Effective date for practitioners' reports dated on or after May 1, 2017
- Timeline event for SSAE 18 effectiveness
- https://www.claconnect.com/en/resources/tools/frequently-asked-questions-about-sas-70-now-ssae-16
Supports
- SAS 70 to SSAE 16 transition and June 15, 2011 period-end effectiveness
- SSAE 18 required for SOC reports issued after May 1, 2017
- Timeline events for SAS 70 era end and SSAE succession
- https://roosacpa.com/sas70/
Supports
- SAS 70 April 1992 origin and role for service organization reporting
- SSAE 16 replacing SAS 70 and SOC 1/2/3 report split
- Timeline events for SAS 70 and SOC branding
- https://www.iso.org/isoiec-27001-information-security.html
Supports
- ISO/IEC 27001 as certifiable ISMS alternative or companion to SOC 2
- Learner reference next-step rationale
- https://www.fedramp.gov/
Supports
- FedRAMP as US federal cloud authorization path distinct from SOC 2
- Learner reference next-step rationale
- https://scadable.com/blog/common-soc2-mistakes
Supports
- Field Notes mistake, difficulty, and tradeoff cards on early clock, evidence scramble, and wide scope
- https://protects.co/soc-2-readiness-fails-when-evidence-is-treated-as-a-document/
Supports
- Field Notes difficulty card on evidence as operational trail versus reconstructed documents
- https://drata.com/learn/soc-2/top-mistakes
Supports
- Field Notes mistake card on starting Type 2 reporting period before controls operate
- https://www.scrut.io/hub/soc-2/soc-2-compliance-timeline
Supports
- Field Notes tradeoff card on scope creep and evidence burden
- https://github.com/getprobo/awesome-compliance
Supports
- Discovery source for Awesome Links tooling and adjacent frameworks
- https://www.soc2.fyi/
Supports
- Awesome Links entry comparing SOC 2 solution approaches
- https://github.com/getprobo/probo
Supports
- Awesome Links open-source compliance automation entry
- https://oneleet.com/
Supports
- Awesome Links compliance automation entry
- https://www.scrut.io/
Supports
- Awesome Links compliance automation entry
- https://trivy.dev/
Supports
- Awesome Links scanner used for technical evidence inputs
- https://wazuh.com/
Supports
- Awesome Links security monitoring platform entry
- https://cloudsecurityalliance.org/star/
Supports
- Awesome Links adjacent cloud assurance program
- https://www.iso27001security.com/
Supports
- Awesome Links practitioner forum for parallel ISO 27001 programs
