Glossary
SOC 2
Also called: SOC 2 Type II, service organisation control
SOC 2 is an attestation report in which an independent accounting firm describes and tests a service organisation's controls against the AICPA trust services criteria. It is not a certification and has no pass mark — the exceptions it records are the informative part.
SOC 2 explained
Type I and Type II
Type I describes controls at a point in time. Type II tests whether they operated across a period, usually six or twelve months, and it is the one enterprise buyers ask for. A Type I report is a reasonable interim position for a younger vendor and should be described as such rather than offered as equivalent.
The five criteria
Security, availability, processing integrity, confidentiality and privacy. Security is in every report; the rest are included by choice. A report covering security alone is normal, and a vendor should tell you which criteria are in scope rather than let you assume all five.
What to read
Section IV, where the testing detail and any exceptions are recorded. Then the observation period, because a report covering a window that closed fourteen months ago describes a system that has changed. Then the complementary user entity controls — obligations transferred to you, which are routinely ignored.
Bridge letters
A bridge or gap letter covers the interval between the end of the report period and the present. In any procurement running more than a few months past the report date it is a standard request, and a vendor unable to provide one is telling you something about their audit cadence.
FAQ
SOC 2: common questions
Is SOC 2 better than ISO 27001?
They answer different questions — ISO certifies that a management system exists and runs; SOC 2 describes and tests specific controls and reports exceptions. If you can only ask for one, ask for the one your auditors understand.
Should we accept a report we cannot see?
No. A vendor unwilling to share under NDA is asking to be taken on trust, and enterprise reviewers treat that as a finding rather than a formality.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
Last reviewed: 28 August 2026. Browse the full glossary.