What is SOC 2?
An independent audit report on a service organization's controls, covering security, availability and related trust criteria over a defined period.

SOC 2 — SOC 2 is an audit report, issued by an independent CPA firm, on a service organisation's controls for security, availability, processing integrity, confidentiality and privacy over a period. It is evidence about the vendor's controls, not a certification of the product.
Why it matters
SOC 2 is a report, not a badge. An outside CPA firm examines a service vendor's controls against a defined set of trust service criteria. Those can include security, availability, processing integrity, confidentiality and privacy. The firm issues a report describing what it found over a specific period. It is evidence about how well the controls were designed. In a Type II report, it also covers whether they operated effectively over that period. It is not a one-time stamp of approval that applies forever afterward.
The distinction that matters most for anyone judging a vendor is between the company and the product. A SOC 2 report speaks to the company's controls. Access management, change management, incident response, monitoring. It does not say a specific product is flawless or bug-free. A website that states "SOC 2 compliant" is making a claim that cannot be checked from that sentence alone. The report itself specifies which trust criteria were in scope, which systems were covered, and the exact period examined. Any of those can be narrower than the sentence on the website implies.
How a SOC 2 report comes about
- 1
Trust criteria are scoped
The company defines which criteria, security, availability, and others, the audit will cover.
- 2
Controls are designed and documented
Policies and technical controls for those criteria are put in place.
- 3
An outside CPA firm examines them
The firm checks whether the controls are designed well.
- 4
Operation is tested over a period
For a Type II report, the firm checks whether controls operated effectively over that time.
- 5
A report is issued
The findings, scope and period are documented in the final report.
The mistake to watch for
Questions
- How is SOC 2 different from ISO 27001?
- SOC 2 is an audit report against trust service criteria, common in the US and issued by a CPA firm. ISO 27001 is an international certification against a formal information security management standard. It is issued by an approved certification body, with a different scope and process.
- Does SOC 2 certify a specific product?
- No. It reports on the company's controls, such as access management and incident response, over a defined period. It does not say any single product is free of defects.
- What should someone ask for beyond the claim of SOC 2 compliance?
- The actual report. It states which trust criteria were in scope, which systems were covered, and the specific period examined. A general claim on a website can be narrower than it sounds.