Purpose
A SOC 2 engagement evaluates controls at a service organization against selected Trust Services Criteria and the organization’s description of its system.
Type I and Type II
A Type I report addresses control design at a point in time. A Type II report also addresses operating effectiveness over a defined period.
Read the scope
The report’s boundaries, services, locations, period, criteria, subservice organizations, complementary controls, exceptions, and auditor opinion determine what assurance it actually provides.
Not a universal certificate
A SOC 2 report does not automatically prove every product, environment, customer configuration, or security objective is covered. Customers still need risk-based review.
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: