SOC 2 Report
A SOC 2 report is an independent attestation that examines a service organization's controls related to one or more Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. It is produced by an external party who evaluates whether those controls are suitably designed and, in some cases, operating effectively. Despite common usage, a SOC 2 is a report rather than a certification, and it does not by itself guarantee that an organization is secure or compliant.
A SOC 2 report is an independent attestation examining a service organization's controls mapped to one or more of the five Trust Services Criteria: Security (the Common Criteria), Availability, Processing Integrity, Confidentiality, and Privacy. A Type 1 report addresses the design of controls as of a point in time, while a Type 2 report evaluates both the design and the operating effectiveness of controls over a defined period. Practitioners should treat a SOC 2 as an attestation report scoped to the criteria the service organization selected, not a certification, and should note its limitations: the scope may exclude criteria not chosen (for example, a security-only report addresses neither privacy nor processing integrity), a Type 1 reflects only a single point in time and can become stale, and the report covers the systems and control boundary defined by the service organization rather than the assessing party's own environment. Reviewing the report's scope, applicable Trust Services Criteria, reporting period, and any noted exceptions is typically necessary before relying on it for third-party assurance.
Why it matters
For third-party assurance, a SOC 2 report is one of the more widely requested pieces of evidence when evaluating a service organization's control environment across the Trust Services Criteria of security, availability, processing integrity, confidentiality, and privacy. It offers an independent attestation rather than a self-reported questionnaire, which is why many programs treat it as a higher-quality input than a vendor's own claims. That distinction matters because independent examination reduces reliance on unverified attestation, though it does not replace the assessing organization's own risk judgment.
Who it's relevant to
Inside SOC 2
Common questions
Answers to the questions practitioners most commonly ask about SOC 2.
