Framework guide • United States

SOC 2: the US trust report, explained

SOC 2 is an AICPA attestation report in which a licensed CPA firm examines how a service organization protects customer data against the Trust Services Criteria. Security is always covered; Availability, Processing Integrity, Confidentiality, and Privacy are optional add-ons. A Type I report tests control design at a point in time, while a Type II report tests how controls operate over a period — the report US SaaS buyers most often ask to read.

What it is

SOC 2 is a reporting framework from the AICPA. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a report describing them and how well they operate. It’s an attestation you share with customers under NDA — not a public certificate — and it’s the security evidence US enterprise buyers most commonly request.

Who needs it

Primarily US-focused SaaS and cloud service providers that store or process customer data. If American enterprise buyers are sending security questionnaires and asking for evidence before signing, SOC 2 is usually what they want. It’s voluntary, but often a gate to winning larger US contracts.

Trust Services Criteria

One required, four optional

Security is mandatory in every SOC 2 report. You add the remaining criteria that match your service and the commitments you make to customers.

Security (required)

The common criteria every SOC 2 report must cover — protection of systems and data against unauthorized access, disclosure, and damage. This is the mandatory baseline.

Availability (optional)

Whether systems are available for operation and use as committed — relevant for anyone offering uptime or SLA commitments to customers.

Processing Integrity (optional)

Whether system processing is complete, valid, accurate, timely, and authorized — important when you process transactions on a customer's behalf.

Confidentiality (optional)

How information designated as confidential is protected throughout its lifecycle — often chosen when you handle sensitive business data.

Privacy (optional)

How personal information is collected, used, retained, disclosed, and disposed of in line with your commitments — relevant when you handle personal data.

Type I

A snapshot. The auditor evaluates whether your controls are suitably designed at a single point in time. It’s faster to reach and a common first step — proof your control design is sound.

Type II

A movie. The auditor tests whether your controls operated effectively over a period — often several months to a year. It carries more weight with buyers because it shows your controls work over time, not just once.

The audit path

From readiness to report

1

Scope & readiness

Decide which Trust Services Criteria apply, define system boundaries, and run a readiness assessment to find gaps before an auditor does.

2

Remediate & implement

Close the gaps — put policies, access controls, monitoring, and evidence collection in place so your controls operate consistently.

3

The audit

A licensed CPA firm examines your controls. A Type I report tests design at a point in time; a Type II report tests operating effectiveness over a period.

4

Report & renew

You receive a SOC 2 report to share with customers under NDA. Most organizations renew annually, typically with a rolling Type II observation window.

Quick comparison

SOC 2 vs ISO 27001

 SOC 2ISO 27001
What it isAttestation report by a CPA firmCertification against a standard
RecognitionPrimarily United StatesInternational
OutputDetailed report to readPass/fail certificate
Built on an ISMS
RenewalTypically annual3-year cycle + surveillance

Want the international certification too? Read our ISO 27001 guide — the controls overlap heavily, so Komply lets you do the work once.

FAQ

SOC 2, answered

Get SOC 2-ready, faster

Komply maps the Trust Services Criteria into one control set, drafts your policies, and tracks evidence — so you walk into your CPA examination prepared.