Ir para o conteúdo principal
DocumentMS

Glossary

SOC 2

Also called: SOC 2 Type II, service organisation control

SOC 2 is an attestation report in which an independent accounting firm describes and tests a service organisation's controls against the AICPA trust services criteria. It is not a certification and has no pass mark — the exceptions it records are the informative part.

SOC 2 explained

Type I and Type II

Type I describes controls at a point in time. Type II tests whether they operated across a period, usually six or twelve months, and it is the one enterprise buyers ask for. A Type I report is a reasonable interim position for a younger vendor and should be described as such rather than offered as equivalent.

The five criteria

Security, availability, processing integrity, confidentiality and privacy. Security is in every report; the rest are included by choice. A report covering security alone is normal, and a vendor should tell you which criteria are in scope rather than let you assume all five.

What to read

Section IV, where the testing detail and any exceptions are recorded. Then the observation period, because a report covering a window that closed fourteen months ago describes a system that has changed. Then the complementary user entity controls — obligations transferred to you, which are routinely ignored.

Bridge letters

A bridge or gap letter covers the interval between the end of the report period and the present. In any procurement running more than a few months past the report date it is a standard request, and a vendor unable to provide one is telling you something about their audit cadence.

FAQ

SOC 2: common questions

Is SOC 2 better than ISO 27001?

They answer different questions — ISO certifies that a management system exists and runs; SOC 2 describes and tests specific controls and reports exceptions. If you can only ask for one, ask for the one your auditors understand.

Should we accept a report we cannot see?

No. A vendor unwilling to share under NDA is asking to be taken on trust, and enterprise reviewers treat that as a finding rather than a formality.

Uma sessão de 30 minutos com um engenheiro de soluções, sobre uma estrutura de pastas e uma cadeia de aprovação parecidas com as suas — não um ambiente de demonstração genérico.