What is SOC 2?
SOC 2 is a reporting framework for service organisations published by the American Institute of Certified Public Accountants. This page explains what a SOC 2 report is, who is allowed to issue one, what the Trust Services Criteria cover, and why SOC 2 is not a certification.
What SOC 2 actually is
SOC stands for System and Organization Controls. SOC 2 is one of the reporting options in that family, published by the American Institute of Certified Public Accountants (AICPA). It is used by service organisations, typically technology and outsourced service providers, to give their customers independent assurance about the controls they operate over customer data and systems.
A SOC 2 engagement is an examination performed by an independent licensed CPA firm under AICPA attestation standards, specifically AT-C section 105, Concepts Common to All Attestation Engagements, and AT-C section 205, Examination Engagements. The evaluation criteria come from TSP section 100, the 2017 Trust Services Criteria with revised points of focus issued in 2022.
The subject matter is the service organisation description of its own system together with the controls stated in that description. The deliverable is a report that contains the practitioner opinion. It is not a certificate.
Why SOC 2 is an attestation and not a certification
This distinction is the single most misunderstood point about SOC 2, so it is worth stating plainly.
- There is no accreditation body for SOC 2 and no public register of organisations that hold one.
- There is no Stage 1 documentation audit followed by a Stage 2 implementation audit. That two stage sequence belongs to ISO management system certification.
- There is no annual surveillance audit and no three year certification cycle.
- No certificate is issued. What is issued is a report, addressed to the service organisation, that its customers and their auditors read under a non disclosure agreement.
- ISO certification bodies do not issue SOC 2 reports in that capacity. The engagement must be performed by a CPA firm.
Because of this, the phrase SOC 2 certified is not accurate. An organisation completes a SOC 2 examination and holds a SOC 2 Type 1 or Type 2 report.
The five Trust Services Criteria categories
A SOC 2 examination is scoped by choosing which of the five categories apply. Security is always in scope. The other four are selected on the basis of the commitments the organisation has made to its customers.
- Security. The common criteria. Protection of information and systems against unauthorised access, unauthorised disclosure and damage. Included in every SOC 2 report.
- Availability. Whether the system is available for operation and use as committed or agreed.
- Processing integrity. Whether system processing is complete, valid, accurate, timely and authorised.
- Confidentiality. Whether information designated as confidential is protected as committed or agreed.
- Privacy. Whether personal information is collected, used, retained, disclosed and disposed of in line with the commitments in the organisation privacy notice.
What a SOC 2 report contains
- The independent service auditor report, which carries the opinion.
- The assertion of the management of the service organisation.
- The description of the system, including its boundaries, the services provided, the infrastructure and software, the people and procedures, and the commitments made to user entities.
- The applicable trust services criteria, the related controls, and for a Type 2 report the tests the service auditor performed and the results of those tests.
- Any other information provided by the service organisation, which sits outside the scope of the opinion.
Complementary user entity controls and complementary subservice organisation controls are also identified, because some criteria can only be met if the customer or a subservice provider does its part.
How a SOC 2 engagement runs in practice
- Define the system and the boundary that the report will cover, including which products, environments and locations are in scope.
- Select the trust services categories, starting from security and adding others based on customer commitments and contractual obligations.
- Carry out a readiness assessment against the criteria to identify gaps in control design and in evidence.
- Remediate the gaps, which usually means writing and approving policies, formalising access review, change management, vendor management and incident response, and putting monitoring in place.
- Operate the controls for the observation period if a Type 2 report is the goal, generating evidence as you go rather than reconstructing it later.
- Undergo the examination by the CPA firm, which tests the controls and evaluates the description.
- Receive the report and share it with customers under a non disclosure agreement.
One structural point matters here. The CPA firm that issues the opinion cannot also design and implement the controls it is opining on, because that would compromise independence. This is why organisations normally use a separate readiness partner and then appoint the CPA firm for the examination itself.
How Univate supports SOC 2 readiness
Univate works on the readiness side of a SOC 2 programme. That covers scoping the system and its boundary, selecting the trust services categories that match your customer commitments, mapping existing controls to the criteria, closing design gaps, setting up the evidence collection that a Type 2 observation period demands, and preparing your teams for the fieldwork.
We do not issue SOC 2 reports and no consultancy can. The opinion has to come from an independent licensed CPA firm, and keeping readiness work separate from the examination is what protects the independence of that opinion. Where an organisation is also pursuing ISO/IEC 27001, we map the two sets of requirements onto one control environment so the same evidence serves both.
SOC 2 questions we are asked most often
Is SOC 2 a certification?
No. SOC 2 is an attestation engagement carried out under the attestation standards of the American Institute of Certified Public Accountants. The output is a report containing an independent practitioner opinion, addressed to the service organisation. There is no certificate, no accreditation body, no national register of SOC 2 holders and no ISO style Stage 1 and Stage 2 audit sequence. The accurate phrasing is that an organisation has completed a SOC 2 examination and holds a SOC 2 report, not that it is SOC 2 certified.
Who is allowed to perform a SOC 2 examination?
Only an independent licensed CPA firm. A SOC 2 examination is an attestation service, so the practitioner must be a CPA firm that is independent of the service organisation in both fact and appearance. ISO certification bodies such as Bureau Veritas, SGS or BSI do not issue SOC 2 reports in that capacity. A consultancy can prepare an organisation for the examination, but it cannot issue the opinion.
What is the difference between SOC 2 Type 1 and SOC 2 Type 2?
A Type 1 report gives an opinion on whether the description of the system is fairly presented and whether the controls are suitably designed as at a specified date. A Type 2 report covers the same ground and adds an opinion on whether those controls operated effectively throughout a specified period, supported by the tests the service auditor performed and the results of those tests.
Which Trust Services Criteria have to be included?
The security category, known as the common criteria, is included in every SOC 2 examination. Availability, processing integrity, confidentiality and privacy are optional and are selected according to the commitments the service organisation has made to its user entities and the nature of the service it provides.
Does a SOC 2 report expire?
A SOC 2 report does not carry an expiry date in the way an ISO certificate does. It describes a point in time for a Type 1 report or a defined period for a Type 2 report. In practice customers expect a fresh report each year. Where the reporting period ends before a customer needs assurance, the service organisation may issue a bridge letter confirming that no material changes have occurred since the period end. A bridge letter is a statement by management and is not covered by the service auditor opinion.
Is SOC 2 the same as ISO 27001?
No. They overlap heavily in subject matter but the mechanics are completely different. ISO/IEC 27001 is a certifiable management system standard, audited by a certification body that is itself accredited, with a certificate valid for three years and annual surveillance audits. SOC 2 produces a report from a CPA firm against the Trust Services Criteria, with no certificate and no surveillance cycle. Many organisations maintain both because different customers ask for different evidence.
Need help achieving this certification? Univate Global delivers end-to-end implementation in 9 markets. Book a free consultation today.
Related Services & Resources
Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.








