SOC 2
An AICPA attestation report on a service organisation's controls against the Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy.
SOC 2 reports come in two types. A Type I describes controls and assesses their design at a point in time. A Type II additionally tests operating effectiveness across a period, usually six to twelve months — which is the one customers actually want, and the only one that says anything about whether controls worked.
Security is the sole required criterion; the other four are included at the organisation’s election. Adding criteria expands the report’s usefulness and its cost, so the choice is commercial as much as technical.
The overlap with ISO 27001 is substantial — the compliance map records 61 SOC 2 criteria against 93 ISO 27001 Annex A controls, with heavy convergence in access, change and incident management. Organisations pursuing both should design to a unified control set from the start rather than running two programmes and reconciling later, because the reconciliation is far more expensive than the design.
For internal audit, SOC 2 reports from vendors are also evidence — and the complementary user entity controls listed at the back are the part almost nobody reads, despite being the part that assigns work to you.
Related