SOC 2 is a US-centric attestation report, governed by the AICPA (American Institute of CPAs) and audited by licensed CPA firms, evaluating a company's controls against the Trust Services Criteria. Unlike a certification, it's an auditor's written opinion — and it's become the default trust signal US SaaS and cloud companies show enterprise customers.
The Trust Services Criteria
SOC 2 is built around five possible criteria: security (mandatory for every report), availability, processing integrity, confidentiality, and privacy. An organization scopes its audit to whichever criteria are actually relevant — a company with strict uptime commitments might include availability; one handling highly sensitive personal data might add privacy.
Type I vs. Type II
A Type I report checks whether controls are designed correctly at one point in time — a snapshot. A Type II report checks whether those same controls actually operated effectively over an observation window, commonly 3–12 months. Type II is significantly more meaningful to a customer evaluating a vendor, since it's evidence of sustained behavior, not a design review.
How it's different from a certification
SOC 2 doesn't produce a certificate; it produces a detailed report with the auditor's opinion, meant to be read (usually under NDA) by the customers and prospects who request it. This is a real structural difference from ISO 27001, which produces a pass/fail certification that's often displayed publicly. See how SOC 2 compares to ISO 27001 for the full picture.
The GRC work behind it
Preparing for a SOC 2 audit is standard GRC work: writing and maintaining policies mapped to the relevant Trust Services Criteria, collecting audit evidence continuously through the observation window, and tracking gaps in a risk register well before the auditor shows up.