Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

Assurance reportAdvanced

SOC 2

SOC 2 reports provide independent assurance about a service organization’s controls relevant to security, availability, processing integrity, confidentiality, or privacy.

Purpose

A SOC 2 engagement evaluates controls at a service organization against selected Trust Services Criteria and the organization’s description of its system.

Type I and Type II

A Type I report addresses control design at a point in time. A Type II report also addresses operating effectiveness over a defined period.

Read the scope

The report’s boundaries, services, locations, period, criteria, subservice organizations, complementary controls, exceptions, and auditor opinion determine what assurance it actually provides.

Not a universal certificate

A SOC 2 report does not automatically prove every product, environment, customer configuration, or security objective is covered. Customers still need risk-based review.

Certification relevance

This subject appears in or supports the following certification bodies of knowledge:

ISACA CISAISC2 CISSP

Authoritative sources