SOC 2: the US trust report, explained
SOC 2 is an AICPA attestation report in which a licensed CPA firm examines how a service organization protects customer data against the Trust Services Criteria. Security is always covered; Availability, Processing Integrity, Confidentiality, and Privacy are optional add-ons. A Type I report tests control design at a point in time, while a Type II report tests how controls operate over a period — the report US SaaS buyers most often ask to read.
What it is
SOC 2 is a reporting framework from the AICPA. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a report describing them and how well they operate. It’s an attestation you share with customers under NDA — not a public certificate — and it’s the security evidence US enterprise buyers most commonly request.
Who needs it
Primarily US-focused SaaS and cloud service providers that store or process customer data. If American enterprise buyers are sending security questionnaires and asking for evidence before signing, SOC 2 is usually what they want. It’s voluntary, but often a gate to winning larger US contracts.
One required, four optional
Security is mandatory in every SOC 2 report. You add the remaining criteria that match your service and the commitments you make to customers.
Security (required)
The common criteria every SOC 2 report must cover — protection of systems and data against unauthorized access, disclosure, and damage. This is the mandatory baseline.
Availability (optional)
Whether systems are available for operation and use as committed — relevant for anyone offering uptime or SLA commitments to customers.
Processing Integrity (optional)
Whether system processing is complete, valid, accurate, timely, and authorized — important when you process transactions on a customer's behalf.
Confidentiality (optional)
How information designated as confidential is protected throughout its lifecycle — often chosen when you handle sensitive business data.
Privacy (optional)
How personal information is collected, used, retained, disclosed, and disposed of in line with your commitments — relevant when you handle personal data.
Type I
A snapshot. The auditor evaluates whether your controls are suitably designed at a single point in time. It’s faster to reach and a common first step — proof your control design is sound.
Type II
A movie. The auditor tests whether your controls operated effectively over a period — often several months to a year. It carries more weight with buyers because it shows your controls work over time, not just once.
From readiness to report
Scope & readiness
Decide which Trust Services Criteria apply, define system boundaries, and run a readiness assessment to find gaps before an auditor does.
Remediate & implement
Close the gaps — put policies, access controls, monitoring, and evidence collection in place so your controls operate consistently.
The audit
A licensed CPA firm examines your controls. A Type I report tests design at a point in time; a Type II report tests operating effectiveness over a period.
Report & renew
You receive a SOC 2 report to share with customers under NDA. Most organizations renew annually, typically with a rolling Type II observation window.
SOC 2 vs ISO 27001
| SOC 2 | ISO 27001 | |
|---|---|---|
| What it is | Attestation report by a CPA firm | Certification against a standard |
| Recognition | Primarily United States | International |
| Output | Detailed report to read | Pass/fail certificate |
| Built on an ISMS | ||
| Renewal | Typically annual | 3-year cycle + surveillance |
Want the international certification too? Read our ISO 27001 guide — the controls overlap heavily, so Komply lets you do the work once.
SOC 2, answered
Get SOC 2-ready, faster
Komply maps the Trust Services Criteria into one control set, drafts your policies, and tracks evidence — so you walk into your CPA examination prepared.