SOC 2 is not a certification issued by the AICPA. It is an independent attestation examination of a service organization’s system description and relevant controls, resulting in a SOC 2 report. Companies commonly say they are “SOC 2 certified” or need a “SOC 2 audit,” but the formal deliverable is the examination report.
The report gives customers and business partners information about controls at a provider they rely on. It does not guarantee that security incidents or service failures are impossible. The organization’s system, selected Trust Services Criteria, evidence, and engagement terms determine what the report actually says.
What is SOC 2?
SOC 2 is an assertion-based examination for service organizations. Management describes the system that delivers a service and the controls relevant to the examination. An independent CPA practitioner evaluates that description and the applicable controls against the AICPA Trust Services Criteria.
This is especially relevant when a company outsources technology, data processing, hosting, or other operations. Customers may need information about how their provider identifies and manages risks. A SOC 2 report supplies that third-party assurance in a structured form.
#1 Best Overall
The AICPA’s available criteria resource is 2017 Trust Services Criteria (With Revised Points of Focus – 2022). The AICPA SOC 2 guide page states that its guide was updated October 15, 2022, and includes implementation guidance for the 2017 criteria with the 2022 revised points of focus, revised implementation guidance for the 2018 Description Criteria, and illustrative reports.
What does a SOC 2 examination cover?
The examination covers the service organization’s described system and the controls relevant to the criteria selected in the engagement. The five possible Trust Services Criteria areas are:
Security
Security concerns protection of the system against unauthorized access, use, or modification. The exact controls examined depend on the service and its system boundary.
Availability
Availability concerns whether the system is available for operation and use as committed or agreed. Scope may include controls related to resilience, monitoring, maintenance, and response when those controls are relevant to the described service.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
Processing integrity
Processing integrity concerns whether system processing is complete, valid, accurate, timely, and authorized for its intended purpose.
Confidentiality
Confidentiality concerns protecting information designated as confidential from unauthorized access or disclosure. The relevant data and safeguards are organization-specific.
Privacy
Privacy concerns the collection, use, retention, disclosure, and disposal of personal information in line with an organization’s privacy commitments and applicable criteria.
A SOC 2 engagement does not automatically include all five areas. The selected criteria should match the service, the system, customer expectations, and the engagement agreement.
Why the system boundary and description matter
A SOC 2 report is about a defined system, not an entire company by default. The organization must describe the service, infrastructure, software, people, procedures, and relevant third parties that make up the system in scope. It should also explain boundaries and exclusions clearly.
Customers should read the system description alongside the control results. A strong control outside the described boundary does not answer a question about a service that the report excludes. Conversely, a narrow, accurate boundary can make the report easier to understand and the examination more focused.
How do I get SOC 2 certified?
“Get certified” is common search language, but the practical objective is to complete a SOC 2 examination and receive the resulting report. Start with the service and system your customers need assurance about, then set scope with an experienced CPA practitioner.
- Define the service and system. Identify the product, environments, data, personnel, facilities, and third parties that support the service. Write a concrete boundary rather than describing the whole business by default.
- Ask customers what they need. Prospects, customers, and business partners may expect different criteria areas or report details. Confirm those expectations before fixing the engagement scope.
- Select the relevant criteria. Choose security and any additional areas—availability, processing integrity, confidentiality, or privacy—that fit the service and customer requirements.
- Engage a qualified CPA firm. Discuss the system description, criteria, evidence expectations, reporting terms, and readiness with a practitioner experienced in SOC examinations.
- Document and operate controls. Establish policies, access processes, change management, monitoring, incident response, vendor oversight, and other controls that are actually relevant to the defined system. Keep evidence as work occurs.
- Resolve gaps before fieldwork. A readiness review can identify missing documentation or inconsistent operation. Correct gaps and retain evidence rather than promising controls that are not operating.
- Complete the examination. The practitioner evaluates management’s description and the relevant controls, then issues the report under the agreed terms.
Readiness software and evidence-management tools can help organize documentation, but they do not perform the independent examination. The CPA firm is responsible for the examination and report.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsSOC 2 Type 1 vs. Type 2
Type 1 and Type 2 are common terms in SOC discussions, but the official pages considered here do not establish enough detail to give a universal comparison of examination periods or recommend one type for every organization. Confirm the applicable current AICPA guidance and the prospective practitioner’s explanation before choosing.
Ask the CPA firm exactly what period, control population, testing approach, exceptions, and report language will apply to your engagement. Customer procurement requirements should be part of that conversation.
How long does SOC 2 take?
There is no universal duration established by the official sources. Timing depends on the system boundary, criteria scope, number of locations and vendors, control maturity, evidence readiness, and the engagement agreement. A provider with a clearly documented system and consistently retained evidence may have a different schedule from one still designing basic controls.
Do not promise customers a fixed completion date until the system, scope, readiness work, and practitioner schedule are defined. Ask for a written timeline that separates preparation, any readiness work, examination procedures, remediation, and report issuance.
SOC 2 vs. SOC 3: which report is different?
| Reader’s need | Better description | Distribution and use |
|---|---|---|
| A customer or business partner needs detailed information about a provider’s controls | SOC 2 report | Detailed examination report; readers should follow the report’s distribution terms. |
| An organization wants a less detailed report for broad public use | SOC 3 report | The AICPA describes SOC 3 as less detailed and freely distributable. |
SOC 3 is not a simpler certification, and SOC 2 does not automatically cover every Trust Services Criteria area. The actual scope remains specific to the organization’s system and engagement.
What a SOC 2 report can—and cannot—tell customers
- It can explain the system in scope, the selected criteria, management’s description, relevant controls, and the practitioner’s reported results under the engagement terms.
- It can support a customer’s vendor-risk review and provide independent information about a service provider’s control environment.
- It cannot guarantee that an incident, outage, inaccurate processing, or unauthorized disclosure will never occur.
- It cannot answer questions about services, systems, locations, or criteria that the report excludes.
Questions to ask before signing an engagement
- Which service and system components are inside the boundary, and what is excluded?
- Which Trust Services Criteria areas do customers actually require?
- What evidence must be retained, in what format, and for what period?
- How will complementary controls at customers or subservice organizations be handled?
- What exceptions or limitations would appear in the report?
- What distribution restrictions apply to the finished report?
- What schedule and fees are stated in the engagement agreement?
Optional deeper reference
The AICPA’s SOC 2 reporting guide is written for practitioners and service-organization managers. The publisher lists an ebook and print-on-demand formats and gives ISBN 978-1-95515-910-4. Treat it as an optional technical reference, not a prerequisite for a beginner.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




