HomeFrameworksInformation Security & PrivacySOC 2

Framework  Information Security & Privacy

SOC 2

SOC 2 is the AICPA's examination of a service organization's controls against the Trust Services Criteria for security (required in every report), availability, processing integrity, confidentiality and privacy. The current criteria are the 2017 Trust Services Criteria with revised points of focus issued in 2022.

A licensed CPA firm examines the organization's system description and controls and issues a report that is restricted to customers, prospects under NDA and their advisers. It has become the default assurance document for SaaS and cloud vendors selling to businesses.

A Type 1 report covers the design of controls at a point in time; a Type 2 report covers design and operating effectiveness over a period, commonly three to twelve months.

To get either, the organization must produce a system description that meets the AICPA description criteria, a management assertion, and a set of written policies and control activities mapped to each criterion in scope.

The auditor tests against those documents, so policies for access, change management, vendor management, incident response, risk assessment, business continuity and data handling need to exist and be followed.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSecurity policy v4by name, on record
Type II Every Daywith AllyMatter
Trust, the Modern WayThe policies your SOC 2 auditor samples first, acknowledged by name
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee on record
Who read which version, and when, for the whole period
03
Hand the CPA firm the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary and contractual. Technology and outsourced service providers obtain SOC 2 because customer security reviews, procurement policies and contracts require it; there is no legal mandate.

What the assessor asks to see

System description and management assertion; trust services categories in scope; policy set (information security, access control, change management, incident response, vendor management, business continuity, data classification and retention, acceptable use); risk assessment; control matrix mapped to criteria; populations and samples for user access, changes, incidents, vendors and hires; monitoring evidence (vulnerability scans, logging, backups, availability metrics); subservice organization reports; board or management oversight records.

Where the requirement sits: CC1.1 (integrity/ethics - code of conduct acknowledgment); CC1.4 (competence); CC2.2, CC2.3 (internal/external communication of policies); CC5.3 (policies and procedures)

Type 1 versus Type 2

Type 1 reports on whether controls are suitably designed and implemented at a single date. Type 2 reports on whether they also operated effectively throughout a period, with sample testing across that period. Buyers increasingly ask for Type 2, and many organizations skip Type 1 or use it only as a first milestone.

What AllyMatter does here

The policy and acknowledgment layer inside SOC 2 (CC1.1, CC2.2, CC5.3).

AllyMatter publishes this site.

Assessors

Who assesses SOC 2

A licensed CPA firm (independent certified public accountants) performing the examination under the AICPA attestation standards and issuing the service auditor's report. Accredited by State board CPA licensure and the AICPA peer review program; no scheme-level accreditor and no public registry of SOC auditors.

No firm has claimed a SOC 2 assessor listing yet. Claim yours →

Consultants

Who helps with SOC 2

A very large ecosystem: compliance automation platforms, readiness consultancies and the advisory arms of CPA firms. They scope trust services categories, write policies, map controls, collect evidence and run mock audits. Typical shape is a readiness phase, a Type 1 or a short first Type 2 period, then annual Type 2 reports.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TruvantisSan Francisco, CA, USANot yet verified
What they do
Full-service GRC + vCISO
Who they help
Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
vCISO.comPittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IsecurionBangalore, IndiaNot yet verified
What they do
ISO 27001 / SOC 2
Who they help
Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Illume IntelligenceCalicut, Kerala, IndiaNot yet verified
What they do
Pentest + SOC 2 readiness
Who they help
Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Precursor SecurityLeeds, UKNot yet verified
What they do
ISO 27001 + CREST pentest
Who they help
Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. AICPA revises guidance on applying its Trust Services Criteria and SOC 2 description criteriaA Big Four summary of what the revised AICPA guidance changes for practitioners and for the description management writes.EY
  2. SOC 2 Trust Services Criteria (TSC) explainedAn audit firm walks through each trust services category and the control expectations behind it, in the auditor's own words.Schellman

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for SOC 2

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of SOC 2 in AllyMatter

Approve the policies SOC 2 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.