Skip to content
FioSec Consulting

Frameworks · Compliance & contractual

SOC 2 (Trust Services Criteria)

The report your customers ask for to trust you with their data.

Maintained by
American Institute of Certified Public Accountants (AICPA)
Origin
United States · widely used across North America
Certifiable?
Not a certificate. An independent CPA firm issues an attestation report.

What it is

SOC 2 is an independent examination of how well a service organization protects the data it handles for its customers. The output is not a certificate but a detailed report, written by a licensed CPA firm, that the service provider can share with customers and prospects under NDA as evidence that its controls are real and operating.

It exists because so many businesses now run on outside software and service providers. Rather than every customer auditing every vendor, the vendor gets examined once against a common standard and hands over the resulting report. It has become a near-default expectation for SaaS and technology providers selling to other businesses.

The examination is performed against the AICPA’s Trust Services Criteria. A SOC 2 report describes the provider’s systems, the controls in place, and, for the more rigorous Type II, the auditor’s testing of whether those controls operated effectively over a period of time.

How it's structured

SOC 2 is built on five Trust Services Criteria. Only the first, Security (the "Common Criteria"), is mandatory; the other four are included only if they are relevant to the service you provide and the promises you make to customers. The Security criterion itself draws heavily on the COSO internal-control concepts: governance, risk, access, change management, and monitoring.

Just as important is the report type. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report tests whether they actually operated effectively across a period (commonly several months to a year). Customers increasingly expect Type II, because design without proven operation means little.

Security (Common Criteria)

Mandatory. Protection of systems and data against unauthorized access: governance, access control, change management, risk, and monitoring.

Availability

Optional. The system is available for operation and use as committed: uptime, performance monitoring, and disaster recovery.

Processing Integrity

Optional. System processing is complete, valid, accurate, timely, and authorized.

Confidentiality

Optional. Information designated as confidential is protected as committed: encryption, access restriction, and disposal.

Privacy

Optional. Personal information is collected, used, retained, disclosed, and disposed of in line with the organization’s privacy notice.

Type I vs Type II

Type I means controls are suitably designed at a point in time. Type II means controls are tested as operating effectively over a period. Most customers want Type II.

Who it's for

SOC 2 is aimed squarely at service providers (SaaS companies, managed-service and hosting providers, data processors) that hold or process other organizations’ data and need to prove they protect it.

The trigger is almost always commercial: an enterprise prospect’s procurement or security team asks for your SOC 2 report before they will sign. If you sell business-to-business and handle customer data, expect the request, and treating it as a sales enabler rather than a compliance chore tends to pay off.

It is less relevant if you do not hold customer data on their behalf, or if your customers and regulators specifically ask for ISO 27001 or a Canadian-law obligation instead. Many providers eventually maintain both SOC 2 and ISO 27001 to cover different markets.

How it compares

SOC 2 and ISO 27001 overlap substantially and are often pursued together. The practical difference: ISO 27001 is an international certificate confirming you run a conforming management system, while SOC 2 is a detailed report, written for a North-American audience, describing and testing your actual controls. Work done for one accelerates the other.

SOC 2’s Security criterion lines up well with NIST CSF and the CIS Controls, so a NIST- or CIS-based program is a strong foundation to build a SOC 2 examination on. The frameworks supply the controls, and SOC 2 is the independent attestation that they work.

How it maps to a Layered Defence

SOC 2 is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for SOC 2?

Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Governance & risk

The Common Criteria foundation.

Do you have documented security policies and a defined owner for the security program?
Do you perform and document a regular risk assessment?
Do you manage vendor and sub-processor risk for the services you rely on?

Access & change

Who can do what, and how changes are controlled.

Is access provisioned by role, reviewed regularly, and removed promptly at offboarding?
Is MFA enforced for access to production systems and administrative tools?
Are changes to production reviewed, tested, and approved before release?

Monitoring & response

Detecting and handling issues.

Are systems logged and monitored, with alerting for suspicious activity?
Do you have a documented, tested incident response plan?

Data protection

Confidentiality and privacy commitments.

Is customer data encrypted in transit and at rest?
Do you honour data retention and disposal commitments made in your agreements or privacy notice?

Evidence & readiness

What an auditor will need.

Can you produce evidence that your controls operated consistently over time, not just today?

Type II tests a period, so point-in-time fixes won’t pass.

No email required; scored in your browser, never sent anywhere.

Authoritative source: AICPA SOC 2 / Trust Services Criteria (aicpa-cima.com)

Explore other frameworks

Need help putting SOC 2 into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.