SOC 2 is a security framework that shows customers you handle their data responsibly. It is especially common for SaaS and service providers selling to larger businesses, where a SOC 2 report is often requested during procurement.
What Is SOC 2?
SOC 2 (System and Organization Controls 2) was developed by the American Institute of Certified Public Accountants (AICPA). Rather than a checklist, it asks you to design controls that fit your business and then have an independent auditor confirm they are in place.
The Five Trust Services Criteria
- Security: protection against unauthorised access. This one is required in every SOC 2 report.
- Availability: systems are available as agreed.
- Processing integrity: processing is complete, accurate and authorised.
- Confidentiality: confidential information is protected.
- Privacy: personal information is collected and used appropriately.
Most companies start with Security only, then add other criteria as customers ask for them.
Type I vs Type II
A Type I report checks that controls are designed properly at a single point in time. A Type II report checks that they operated effectively over a period, usually between three and twelve months. Enterprise buyers usually expect Type II.
How The Audit Works
A licensed CPA firm reviews your policies, tests evidence such as access reviews, change records and backups, and interviews your team. The result is a report you can share with customers under NDA.
How To Prepare
Start with a gap analysis against the criteria you need, fix the gaps, then collect evidence over the audit window. Automated monitoring and clear ownership make the Type II period much easier.
Draft copy for layout. Review with the Elite security team before publishing.