SOC 2
Definition
SOC 2
Service Organization Control 2 (SOC 2) is an audit standard from the American Institute of Certified Public Accountants (AICPA) that grades how providers protect customer data. Buyers treat a clean SOC 2 report as the base gate before signing any cloud vendor.
Reports come in two flavors. A Type I attests that controls are properly designed on a single date, while a Type II tests whether those controls actually operated across a six-to-twelve-month observation window, the version most clients now require.
The framework covers five trust services criteria: security, availability, processing integrity, confidentiality, and privacy. Security is always in scope; the other four are elective and drive the audit fee based on which workloads a buyer wants tested.
Key takeaways
- SOC 2 covers five trust services criteria — security is mandatory, the other four are elective.
- Type I is a point-in-time design snapshot; Type II proves controls held over six to twelve months.
- Reports are shared under a non-disclosure agreement (NDA), never posted publicly.
- Buyers ask for the current report and any bridge letter during vendor selection.
How it works
A SOC 2 engagement runs on a fixed cycle. A certified public accountant firm scopes the systems in play, reviews written policies, tests operating controls over a defined window, and issues a signed attestation report the vendor then shares under NDA.
The audit uses the trust services criteria as its yardstick. Security must be in scope; the other four criteria are elected based on what data the buyer cares about.
| Criterion | What the auditor checks | Buyer read |
|---|---|---|
| Security | Access controls, encryption, incident response | Baseline; always in scope |
| Availability | Uptime, backup, recovery testing | Ask when buying hosted software |
| Processing integrity | Data completeness, accuracy | Ask for payments or claims |
| Confidentiality | Handling of restricted data under NDA | Ask for legal or health records |
| Privacy | Personal data collection, notice, choice | Ask when handling personal data |
The AICPA published SOC 2 in 2010 as the successor to SAS 70. Since 2017, the criteria have aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework, which is why buyers accept SOC 2 as control evidence.
Examples
Buyers ask for a SOC 2 report the moment sensitive data crosses a vendor boundary. The same report reads differently across sectors: a payroll processor, a call center, and a healthcare outsourcing firm all pursue SOC 2 but scope in different trust services criteria.
Amazon Web Services (AWS). AWS publishes a fresh SOC 2 Type II report every six months and lists 143 in-scope services in the 2024 edition. Enterprise buyers pull it via AWS Artifact before onboarding a new workload — no report, no procurement approval.
Stripe. The Dublin-headquartered payments firm renews SOC 2 Type II annually and covers all five trust services criteria, a scope choice driven by the processing integrity and cardholder confidentiality demands of its bank and enterprise buyers.
Concentrix. The Newark-based business process outsourcing (BPO) provider carries SOC 2 across many offshore delivery sites. Banks and health insurers demand center-specific reports, so multi-site BPOs run the audit as a parallel workstream in every region.
TaskUs. The New Braunfels-based digital services BPO holds SOC 2 Type II reports across its global delivery sites.
Financial-services and healthcare clients pull the current report before every quarterly business review — a cadence written into master services agreements from 2023 onward.
Related terms
- ISO 27001: international certification for information security management systems, often paired with SOC 2 for global buyers.
- PCI DSS: the payment card industry rulebook that overlaps SOC 2 on processing integrity and confidentiality.
- Business process outsourcing: the delivery model that made SOC 2 attestations a standard buyer requirement.
- Vendor management: the buyer-side function that collects and reviews SOC 2 reports each renewal cycle.
- Data privacy: the individual-rights domain SOC 2 covers under its privacy trust services criterion.
- Cybersecurity: the broader control practice SOC 2 audits and reports against.
- Data security: the umbrella practice SOC 2 documents in a formal, third-party report.
FAQ
What is a SOC 2 report used for?
A SOC 2 report tells a buyer whether an outsourced service provider has designed and operated the right controls over sensitive data. Buyers use it as procurement evidence before signing a contract, and auditors use it to reduce fieldwork on downstream financial audits.
How long does a SOC 2 Type II audit take?
Most Type II audits cover a six to twelve month observation window, plus four to eight weeks of fieldwork. First-time reports run longer because the auditor has to test controls that were not previously documented.
Is SOC 2 the same as ISO 27001?
No. SOC 2 is a US attestation report against the AICPA trust services criteria. ISO 27001 is an international certification against a management system standard, and many global buyers now ask for both.
Do I need SOC 2 to hire an offshore BPO?
Not always, but most enterprise buyers now insist on a current SOC 2 Type II report before signing.
Browse SOC 2-ready outsourcing partners on the Outsource Accelerator directory.







Independent




