Security (Common Criteria)
Mandatory. Protection of systems and data against unauthorized access: governance, access control, change management, risk, and monitoring.
Frameworks · Compliance & contractual
The report your customers ask for to trust you with their data.
SOC 2 is an independent examination of how well a service organization protects the data it handles for its customers. The output is not a certificate but a detailed report, written by a licensed CPA firm, that the service provider can share with customers and prospects under NDA as evidence that its controls are real and operating.
It exists because so many businesses now run on outside software and service providers. Rather than every customer auditing every vendor, the vendor gets examined once against a common standard and hands over the resulting report. It has become a near-default expectation for SaaS and technology providers selling to other businesses.
The examination is performed against the AICPA’s Trust Services Criteria. A SOC 2 report describes the provider’s systems, the controls in place, and, for the more rigorous Type II, the auditor’s testing of whether those controls operated effectively over a period of time.
SOC 2 is built on five Trust Services Criteria. Only the first, Security (the "Common Criteria"), is mandatory; the other four are included only if they are relevant to the service you provide and the promises you make to customers. The Security criterion itself draws heavily on the COSO internal-control concepts: governance, risk, access, change management, and monitoring.
Just as important is the report type. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report tests whether they actually operated effectively across a period (commonly several months to a year). Customers increasingly expect Type II, because design without proven operation means little.
Mandatory. Protection of systems and data against unauthorized access: governance, access control, change management, risk, and monitoring.
Optional. The system is available for operation and use as committed: uptime, performance monitoring, and disaster recovery.
Optional. System processing is complete, valid, accurate, timely, and authorized.
Optional. Information designated as confidential is protected as committed: encryption, access restriction, and disposal.
Optional. Personal information is collected, used, retained, disclosed, and disposed of in line with the organization’s privacy notice.
Type I means controls are suitably designed at a point in time. Type II means controls are tested as operating effectively over a period. Most customers want Type II.
SOC 2 is aimed squarely at service providers (SaaS companies, managed-service and hosting providers, data processors) that hold or process other organizations’ data and need to prove they protect it.
The trigger is almost always commercial: an enterprise prospect’s procurement or security team asks for your SOC 2 report before they will sign. If you sell business-to-business and handle customer data, expect the request, and treating it as a sales enabler rather than a compliance chore tends to pay off.
It is less relevant if you do not hold customer data on their behalf, or if your customers and regulators specifically ask for ISO 27001 or a Canadian-law obligation instead. Many providers eventually maintain both SOC 2 and ISO 27001 to cover different markets.
SOC 2 and ISO 27001 overlap substantially and are often pursued together. The practical difference: ISO 27001 is an international certificate confirming you run a conforming management system, while SOC 2 is a detailed report, written for a North-American audience, describing and testing your actual controls. Work done for one accelerates the other.
SOC 2’s Security criterion lines up well with NIST CSF and the CIS Controls, so a NIST- or CIS-based program is a strong foundation to build a SOC 2 examination on. The frameworks supply the controls, and SOC 2 is the independent attestation that they work.
SOC 2 is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Governance & risk
—Access & change
—Monitoring & response
—Data protection
—Evidence & readiness
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: AICPA SOC 2 / Trust Services Criteria (aicpa-cima.com)
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.