What It Is

SOC 2 is not a cybersecurity framework and not a certification. It is an independent audit report - an examination only a licensed CPA firm can perform, under AICPA attestation standards. That is why "SOC 2 certified" is always the wrong phrase: there is no certificate, there is an auditor's opinion.

The examination evaluates whether your controls are:

  • Designed appropriately (SOC 2 Type I): a point-in-time snapshot of control design.
  • Operating effectively over time (SOC 2 Type II): the same controls, tested across a review period.

The report is based on the Trust Services Criteria (TSC):

  • Security: the baseline - its criteria are AICPA's "common criteria," included in virtually every SOC 2 report.
  • Availability: uptime and resilience commitments.
  • Confidentiality: protection of sensitive business information.
  • Processing Integrity: systems doing what they promise, accurately.
  • Privacy: handling of personal information.

Think of it this way: SOC 2 is proof that your security and operational controls actually work - not just that they exist.

What Information Is Regulated

SOC 2 applies to systems and processes that support your service commitments.

This includes:

  • Production environments: the systems delivering the service you promised.
  • User identities and access: every account that can touch them.
  • Endpoints and servers: the operational estate.
  • Cloud platforms and applications: wherever the service actually runs.
  • Email and collaboration tools: operational systems attackers reach first.
  • Logging, monitoring, and alerting: the evidence-producing layer.
  • Backup and recovery systems: availability commitments made real.
  • Policies, procedures, and governance: the management wrapper auditors test against practice.

If it affects customer trust, it is in scope.

IT Requirements

Ignore trust service jargon. Focus on what must consistently work.

Identity & Access Management

  • Unique user IDs: shared accounts end the conversation.
  • MFA where appropriate: expected on anything that matters.
  • Least-privilege access: rights match roles, nothing extra.
  • Timely access reviews: departures and role changes caught on schedule.

System & Endpoint Security

  • Secure configurations: hardened baselines, maintained.
  • Patch and vulnerability management: known issues fixed on a defensible cadence.
  • Malware protection: deployed, updated, and monitored.

Data Protection

  • Encryption in transit and at rest: the table-stakes control auditors verify first.
  • Secure data handling: classification and procedures followed in practice.
  • Controlled access to sensitive data: who can see it, tracked and justified.

Logging & Monitoring

  • Centralized logging: one place where the evidence accumulates.
  • Alerting on suspicious activity: detection wired to a human response.
  • Evidence of review: logs someone provably looked at.

Incident Response

  • Documented response plan: written before it's needed.
  • Clear roles: who declares, who investigates, who communicates.
  • Testing and lessons learned: exercised, then improved.

Change Management

  • Controlled changes to production: no undocumented pushes.
  • Approvals and testing: review before release, every time.
  • Rollback capability: a way back when a change goes wrong.

Governance & Documentation

  • Policies that reflect reality: auditors compare paper to practice.
  • Defined ownership: every control answers to someone.
  • Evidence of operation: proof produced by daily work.

SOC 2 is about consistency over time.

How It Fits Into Cyber Risk Management

SOC 2 isn't about passing an audit. It's about operating securely, doing it the same way every day, and proving it when asked.

That operating discipline is what our Cyber Risk Management service builds, and the evidence habit is what our GRC service systematizes - so the audit documents a program instead of interrupting one.

Start with controls. Prove with consistency.

How We Help With SOC 2 Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your controls and evidence habits against the Trust Services Criteria - so you walk into the CPA firm's examination knowing what they'll find.

How to Prepare

  1. Define scope and commitments

    You don't start with auditors. You start with operations. Know what systems support your service and what promises you make to customers - the report is an examination of exactly those commitments.

  2. Validate core security controls

    Focus on identity, endpoints, email, data protection, logging, and incident response. These map to most SOC 2 criteria, and they're the controls attackers test before any auditor does.

  3. Document what you actually do

    Auditors test reality, not intent. A modest, followed policy beats an impressive, ignored one in every examination.

  4. Collect evidence continuously

    Logs: retained and reviewable. Screenshots: configurations captured when set. Tickets: work recorded as it happens. Approvals: authorization trails intact. Evidence should be a byproduct of work - not a scramble.

  5. Test over time

    SOC 2 Type II rewards consistency, not heroics. The review period measures months of ordinary operation - make ordinary operation the thing that passes.

Official source

Official source: AICPA & CIMA

Secondary source: AICPA & CIMA - SOC Suite of Services

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25