Audit & Attestation
SOC 2
Trust Services Criteria (SOC 2)
An attestation report by an independent auditor against five trust services criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report covers design at a point in time; Type II covers operating effectiveness over a period.
Not a certification and not a European instrument, but for SaaS vendors it is the de-facto entry ticket, and the Type II report is the evidence pack most third-party risk teams open first.
At a glance
- Category
- Audit & Attestation
- Jurisdiction
- US / Global
- Governance
- AICPA
- Status
- Trust Services Criteria (2017, revised points of focus 2022)
- First released
- 2011
Links
Related frameworks
Other entries under Audit & Attestation.
- ISAE 3402: Assurance Reports on Controls at a Service Organization
See SOC 2 in context
Open the interactive Data Landscape for Regulation to compare SOC 2 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.