Skip to content

SOC 2

What it is

System and Organization Controls 2 — an attestation report, produced by a licensed CPA firm, on how well a service organization’s controls meet the AICPA Trust Services Criteria. It is not a government standard and not a pass/fail “certification”; it’s an auditor’s opinion, delivered as a report you share (under NDA) with customers.

Who it applies to

The default ask in US B2B SaaS sales. Voluntary, but practically mandatory to sell to security-conscious commercial buyers.

Disclaimer. Not legal/compliance advice. Verified 2026-05-29.


The five Trust Services Criteria (TSC)

You always include Security; the other four are optional based on what you commit to:

CriterionCovers
Security (Common Criteria)Required. Protection against unauthorized access.
AvailabilitySystem is available per SLA/commitments.
Processing IntegrityProcessing is complete, valid, accurate, timely.
ConfidentialityInformation designated confidential is protected.
PrivacyPersonal information handled per the privacy notice.

Type I vs Type II

  • Type I — controls are suitably designed at a point in time.
  • Type II — controls operated effectively over a period (typically 3–12 months). Type II is what buyers actually want.

Relationship to the others

SOC 2’s Common Criteria map closely to ISO 27001 Annex A and to a subset of NIST 800-53. If you build to the FedRAMP baseline, a SOC 2 Type II is mostly about collecting evidence that those controls ran — the controls themselves are already there.



Sources (verified 2026-05-29)

ClaimSource
SOC 2 & Trust Services CriteriaAICPA — SOC 2
Trust Services Criteria (2017, rev. 2022)AICPA TSC