SOC 2
What it is
System and Organization Controls 2 — an attestation report, produced by a licensed CPA firm, on how well a service organization’s controls meet the AICPA Trust Services Criteria. It is not a government standard and not a pass/fail “certification”; it’s an auditor’s opinion, delivered as a report you share (under NDA) with customers.
Who it applies to
The default ask in US B2B SaaS sales. Voluntary, but practically mandatory to sell to security-conscious commercial buyers.
Disclaimer. Not legal/compliance advice. Verified 2026-05-29.
The five Trust Services Criteria (TSC)
You always include Security; the other four are optional based on what you commit to:
| Criterion | Covers |
|---|---|
| Security (Common Criteria) | Required. Protection against unauthorized access. |
| Availability | System is available per SLA/commitments. |
| Processing Integrity | Processing is complete, valid, accurate, timely. |
| Confidentiality | Information designated confidential is protected. |
| Privacy | Personal information handled per the privacy notice. |
Type I vs Type II
- Type I — controls are suitably designed at a point in time.
- Type II — controls operated effectively over a period (typically 3–12 months). Type II is what buyers actually want.
Relationship to the others
SOC 2’s Common Criteria map closely to ISO 27001 Annex A and to a subset of NIST 800-53. If you build to the FedRAMP baseline, a SOC 2 Type II is mostly about collecting evidence that those controls ran — the controls themselves are already there.
Related resources
- ISO 27001 — the international counterpart
- Security Overview & decision guide
- FRD: Audit Log Library — evidence the auditor will want
Sources (verified 2026-05-29)
| Claim | Source |
|---|---|
| SOC 2 & Trust Services Criteria | AICPA — SOC 2 |
| Trust Services Criteria (2017, rev. 2022) | AICPA TSC |