SOC 2
Definition
A voluntary security-audit framework from the AICPA that reports on how a service organization manages customer data across five trust criteria.In-Depth Explanation
SOC 2 (System and Organization Controls 2) is based on the AICPA's Trust Services Criteria: Security (required), Availability, Processing Integrity, Confidentiality, and Privacy. A Type I report assesses control design at a single point in time, while a Type II report assesses operating effectiveness over a period, typically 6 to 12 months. Enterprise buyers treat a completed Type II report as strong evidence a vendor handles data securely. Claims like "SOC 2 in progress" or Type I alone are weaker than a finished Type II.
Real-World Example
A SaaS company shares its SOC 2 Type II report with prospective enterprise customers to prove its security controls operate effectively.