SOC 2 report
An independent CPA's report on whether a service company's security controls are well designed and, for Type II, worked over time.
What it is
A SOC 2 report is an independent CPA's examination of controls at a service organization against the AICPA Trust Services Criteria. A Type I report looks at whether the controls are suitably designed at a specific date. A Type II report also tests whether those controls operated effectively across a stated period. It is an attestation report, not a certification and not a public seal of perfect security.
Reach for SOC 2 when enterprise buyers need third-party evidence before they will send you sensitive data. Security is always in scope; availability, processing integrity, confidentiality, and privacy are included only when the engagement covers them. Buyers usually review the detailed report under a nondisclosure agreement.
Gotcha: the cover page is the least interesting part. Read the system description, exact scope, examination period, exceptions, auditor's opinion, and complementary user entity controls. A clean report for one product or an old period does not prove that a newly acquired service or this month's controls were examined.
Ask AI for it
Create a SOC 2 Type II readiness plan for the SaaS company below using the AICPA Trust Services Criteria. Define the system boundary and examination period, map each security criterion to one named control, owner, frequency, and evidence source, and collect evidence from AWS CloudTrail, Okta system logs, GitHub branch protection, Jira tickets, and the incident register. Add control tests for onboarding, offboarding, access reviews, change management, vulnerability handling, backups, and incident response. Produce an exception log, complementary user entity controls, a management assertion outline, and a 12-week remediation schedule without claiming certification.