What is SOC 2?
SOC 2 is a reporting framework from the American Institute of Certified Public Accountants (AICPA). A licensed CPA firm examines the controls at a service organization and reports on them against the Trust Services Criteria.
It is an attestation, not a certification. There is no SOC 2 certificate: you receive a report, which you share with customers, usually under a non-disclosure agreement.
Who asks for SOC 2?
- US enterprise customers, during vendor security reviews and procurement.
- Customers of SaaS and cloud companies that store or process their data.
- Investors and partners doing security due diligence.
No law requires SOC 2. Like ISO 27001, it becomes a requirement when customers ask for it.
The five Trust Services Criteria
Criterion
SecurityRequired?
AlwaysWhat it covers
Protection against unauthorised access, across governance, risk, access, operations and changeCriterion
AvailabilityRequired?
OptionalWhat it covers
Uptime commitments, capacity, backup and disaster recoveryCriterion
Processing integrityRequired?
OptionalWhat it covers
Complete, accurate and timely processingCriterion
ConfidentialityRequired?
OptionalWhat it covers
Protection of information designated as confidentialCriterion
PrivacyRequired?
OptionalWhat it covers
Collection, use, retention and disposal of personal informationSecurity, also called the Common Criteria (CC1 to CC9), is part of every SOC 2. You add the others based on what you promise your customers.
SOC 2 Type I vs Type II
Type I
Whether controls are designed properlyType II
Whether controls are designed properly and worked over timeType I
A single point in timeType II
An observation period, usually 3 to 12 monthsType I
Often accepted as a first stepType II
The report most enterprise buyers ask forHow a SOC 2 audit works
- Choose the scope: the systems in the report and the criteria beyond Security.
- Readiness or gap assessment: compare your controls with the criteria.
- Implement and document the missing controls.
- For Type II, run the controls through the observation period so they produce evidence.
- The CPA firm tests the controls and issues the report.
- Repeat each year: a Type II report covers a fixed period, so customers expect a current one.
Where teams usually fall short
- Access reviews not performed, or not evidenced, on schedule.
- Offboarding that leaves accounts active.
- Changes to production without documented approval and testing.
- No inventory or risk review of critical vendors.
- Security alerts that are generated but not monitored.
- Policies that exist but were never acknowledged by staff.
What the free assessment covers
The free SwaSec SOC 2 assessment asks 13 questions across 11 domains and takes about 10 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.
- CC1: Control Environment. Commitment to integrity, ethical values, board oversight, and organizational structure.
- CC2: Communication and Information. Quality information generation, internal and external communication of control information.
- CC3: Risk Assessment. Risk identification, analysis, and consideration of fraud and change.
- CC4: Monitoring Activities. Ongoing monitoring and periodic evaluation of internal controls.
- CC5: Control Activities. Selection and deployment of control activities that mitigate risks.
- CC6: Logical and Physical Access. Access controls, authentication, and restriction of system access points.
- CC7: System Operations. Detection, response, and recovery from security events and incidents.
- CC8: Change Management. Controlled change management for infrastructure, data, software, and procedures.
- CC9: Risk Mitigation. Vendor risk management and business partner risk mitigation.
- A1: Availability. Additional criteria for availability commitments, redundancy, and disaster recovery.
- C1: Confidentiality. Additional criteria for identification and protection of confidential information.
Start the SOC 2 assessment. It is a self-assessment, not an audit or a certification.
How SOC 2 overlaps with other frameworks
SOC 2 shares 9 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.
- Security Policy, shared with ISO 27001, ISO 42001 and GDPR. Asked once.
- Risk Assessment, shared with ISO 27001, ISO 42001, GDPR and EU AI Act. Asked separately, because each framework wants something different.
- Access Control, shared with ISO 27001. Asked once.
- Incident Response, shared with ISO 27001 and GDPR. Asked once.
- Vendor/Supplier Management, shared with ISO 27001, ISO 42001 and GDPR. Asked once.
- Logging and Monitoring, shared with ISO 27001. Asked once.
- Change Management / Secure Development, shared with ISO 27001 and ISO 42001. Asked once.
- Training and Awareness, shared with ISO 27001 and ISO 42001. Asked once.
- Business Continuity and Recovery, shared with ISO 27001. Asked once.
Frequently asked questions
Is SOC 2 a certification?
No. SOC 2 is an attestation report issued by a licensed CPA firm. There is no SOC 2 certificate, although the phrase is common.
Should I get SOC 2 Type I or Type II?
Many teams start with Type I so they have a report to share sooner, then move to Type II. Ask the customers requesting it which they will accept.
What is the difference between SOC 2 and ISO 27001?
SOC 2 is a report on how specific controls are designed and operate, common with US buyers. ISO 27001 is a certification of your whole information security management system, common internationally. Their controls overlap a great deal.
How often do I need a SOC 2 report?
A Type II report covers a fixed period, so most companies renew it every year to keep a current report available for customers.
What does the free SwaSec SOC 2 assessment cover?
13 questions across 11 domains, taking about 10 minutes, with no signup. It gives you a score for SOC 2, the gaps it found, and the clause, control or article each gap relates to.
Sources
This guide is general information, not legal advice. Last updated 1st October 2026.