• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » SOC 2

SOC 2

Definition

SOC 2

Service Organization Control 2 (SOC 2) is an audit standard from the American Institute of Certified Public Accountants (AICPA) that grades how providers protect customer data. Buyers treat a clean SOC 2 report as the base gate before signing any cloud vendor.

Reports come in two flavors. A Type I attests that controls are properly designed on a single date, while a Type II tests whether those controls actually operated across a six-to-twelve-month observation window, the version most clients now require.

The framework covers five trust services criteria: security, availability, processing integrity, confidentiality, and privacy. Security is always in scope; the other four are elective and drive the audit fee based on which workloads a buyer wants tested.

Key takeaways

  • SOC 2 covers five trust services criteria — security is mandatory, the other four are elective.
  • Type I is a point-in-time design snapshot; Type II proves controls held over six to twelve months.
  • Reports are shared under a non-disclosure agreement (NDA), never posted publicly.
  • Buyers ask for the current report and any bridge letter during vendor selection.

How it works

A SOC 2 engagement runs on a fixed cycle. A certified public accountant firm scopes the systems in play, reviews written policies, tests operating controls over a defined window, and issues a signed attestation report the vendor then shares under NDA.

The audit uses the trust services criteria as its yardstick. Security must be in scope; the other four criteria are elected based on what data the buyer cares about.

CriterionWhat the auditor checksBuyer read
SecurityAccess controls, encryption, incident responseBaseline; always in scope
AvailabilityUptime, backup, recovery testingAsk when buying hosted software
Processing integrityData completeness, accuracyAsk for payments or claims
ConfidentialityHandling of restricted data under NDAAsk for legal or health records
PrivacyPersonal data collection, notice, choiceAsk when handling personal data

The AICPA published SOC 2 in 2010 as the successor to SAS 70. Since 2017, the criteria have aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework, which is why buyers accept SOC 2 as control evidence.

Examples

Buyers ask for a SOC 2 report the moment sensitive data crosses a vendor boundary. The same report reads differently across sectors: a payroll processor, a call center, and a healthcare outsourcing firm all pursue SOC 2 but scope in different trust services criteria.

Amazon Web Services (AWS). AWS publishes a fresh SOC 2 Type II report every six months and lists 143 in-scope services in the 2024 edition. Enterprise buyers pull it via AWS Artifact before onboarding a new workload — no report, no procurement approval.

Stripe. The Dublin-headquartered payments firm renews SOC 2 Type II annually and covers all five trust services criteria, a scope choice driven by the processing integrity and cardholder confidentiality demands of its bank and enterprise buyers.

Concentrix. The Newark-based business process outsourcing (BPO) provider carries SOC 2 across many offshore delivery sites. Banks and health insurers demand center-specific reports, so multi-site BPOs run the audit as a parallel workstream in every region.

TaskUs. The New Braunfels-based digital services BPO holds SOC 2 Type II reports across its global delivery sites.

Financial-services and healthcare clients pull the current report before every quarterly business review — a cadence written into master services agreements from 2023 onward.

Related terms

  • ISO 27001: international certification for information security management systems, often paired with SOC 2 for global buyers.
  • PCI DSS: the payment card industry rulebook that overlaps SOC 2 on processing integrity and confidentiality.
  • Business process outsourcing: the delivery model that made SOC 2 attestations a standard buyer requirement.
  • Vendor management: the buyer-side function that collects and reviews SOC 2 reports each renewal cycle.
  • Data privacy: the individual-rights domain SOC 2 covers under its privacy trust services criterion.
  • Cybersecurity: the broader control practice SOC 2 audits and reports against.
  • Data security: the umbrella practice SOC 2 documents in a formal, third-party report.

FAQ

What is a SOC 2 report used for?

A SOC 2 report tells a buyer whether an outsourced service provider has designed and operated the right controls over sensitive data. Buyers use it as procurement evidence before signing a contract, and auditors use it to reduce fieldwork on downstream financial audits.

How long does a SOC 2 Type II audit take?

Most Type II audits cover a six to twelve month observation window, plus four to eight weeks of fieldwork. First-time reports run longer because the auditor has to test controls that were not previously documented.

Is SOC 2 the same as ISO 27001?

No. SOC 2 is a US attestation report against the AICPA trust services criteria. ISO 27001 is an international certification against a management system standard, and many global buyers now ask for both.

Do I need SOC 2 to hire an offshore BPO?

Not always, but most enterprise buyers now insist on a current SOC 2 Type II report before signing.

Browse SOC 2-ready outsourcing partners on the Outsource Accelerator directory.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image