openskills.info
Course Preview

SOC 2 Compliance

SOC 2 is an AICPA attestation report on how a service organization controls security, and optionally availability, processing integrity, confidentiality, or privacy. A licensed CPA firm examines your system description and controls and issues a Type 1 (design as of a date) or Type 2 (design plus operating effectiveness over a period) report. It is not a certification.

itCybersecurity fundamentals and governance

Don't Panic — SOC 2 Compliance

SOC 2 is the report a licensed CPA firm writes after examining how a service organization controls security (and maybe a few friends: availability, processing integrity, confidentiality, privacy). It is an attestation with an opinion. It is not a certificate, a badge, or a spell that makes breaches impossible.

People used to lean on a single old service-auditor standard for almost everything. The modern split is clearer: SOC 1 when the story is financial reporting controls, SOC 2 when the story is Trust Services detail for customers and risk teams, SOC 3 when you want the same Trust Services idea in a shorter public-facing shape.

Two ideas do most of the carrying. First, the Trust Services Criteria: Security is always in; the other categories join when your commitments make them relevant. Second, Type 1 versus Type 2: Type 1 asks whether the description and design look right as of a date; Type 2 asks whether the controls actually operated across a period and shows the auditor's tests. Enterprise procurement almost always wants Type 2.

The surprise is that the system description and the observation period matter as much as the control list. Carve-outs, subservice cloud providers, and CUECs (the controls your customers must run) decide what the opinion really covers. A six-month Type 2 window that starts before reviews and logging are stable is how you buy exceptions in bulk.

Automation platforms can collect evidence. Only the CPA issues the opinion. A green dashboard is a helpful roommate; it is not the report.

Read the Intro for the full map. Keep the Cheatsheet open when scoping categories and report type. Use the Practice Reference when you map controls and dry-run evidence retrieval. Field Notes is where the costly timing and scope mistakes live. The Exercise is a fictional SaaS scoping drill if you want to practice before a real kickoff.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources