Audit & Attestation

SOC 2

Trust Services Criteria (SOC 2)

Formal standard US / Global AICPA Since 2011

An attestation report by an independent auditor against five trust services criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report covers design at a point in time; Type II covers operating effectiveness over a period.

Not a certification and not a European instrument, but for SaaS vendors it is the de-facto entry ticket, and the Type II report is the evidence pack most third-party risk teams open first.

At a glance

Category
Audit & Attestation
Jurisdiction
US / Global
Governance
AICPA
Status
Trust Services Criteria (2017, revised points of focus 2022)
First released
2011

Links

Related frameworks

Other entries under Audit & Attestation.

See SOC 2 in context

Open the interactive Data Landscape for Regulation to compare SOC 2 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.