SOC 2 report

What is a SOC 2 report?

Definition

A SOC 2 report is an independent examination, performed by a CPA firm under AICPA standards, of a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy. Software and outsourcing providers give it to customers, and their auditors, as evidence that systems holding customer data are properly controlled.

Also calledSOC 2 Type 2SOC 2 Type 1SOC 2 audit

Compare the softwareBest audit software →All 8 audit vendors →

Set by
AICPA
Always covers
Security
Type 2
Controls tested over a period
01

How SOC 2 works

The provider describes its system and chooses which trust services categories to cover; security is included in every SOC 2, and the others are added where relevant. A Type 1 report gives the auditor's opinion on the description and the suitability of the design of controls at a point in time. A Type 2 report adds testing of whether the controls operated effectively over a period, commonly six to twelve months, and is the version most customers ask for. The report lists the controls, the tests and any exceptions, plus complementary user entity controls that customers must operate themselves. SOC 1 is a different report, on controls relevant to customers' financial reporting, such as a payroll or billing provider's; SOC 3 is a short public summary of a SOC 2. Finance teams review vendors' SOC 2 reports when buying finance software, and CPA firms run the engagements on audit platforms such as Fieldguide.

02

Common questions

What is the difference between SOC 2 Type 1 and Type 2?+

Type 1 reports on whether controls are suitably designed at a point in time. Type 2 also tests whether they operated effectively over a period, so it gives customers more assurance.

What is the difference between SOC 1 and SOC 2?+

SOC 1 covers controls relevant to customers' financial reporting, used by their auditors. SOC 2 covers controls over security, availability, processing integrity, confidentiality and privacy, used by customers to assess data risk.

Is SOC 2 a certification?+

No. It is an attestation report with an auditor's opinion, not a certificate. Customers read the report, including any exceptions and the controls they are expected to run themselves.

03

Software used for SOC 2 engagements

Part of Accountio’s accounting technology coverage · Glossary