Table of Contents
- Introduction
- What does SOC 2 Stand for and why was it Developed?
- The Deep Roots of SOC 1, SOC 2, and SOC 3
- How does the SOC 2 Security Framework Align with Compliance, Audit, and Reports?
- What are the Two Types of SOC 2 Reports?
- What are the Details of the Five Trust Services Criteria (TSCs)?
- What is the Common Criteria (or CC-series)?
- The Importance and Advantages of SOC 2 Compliance?
- In Summary
Introduction
The increased outsourcing of many IT business functions such as payroll and accounting, among many others along with growing cybersecurity threats necessitated a security framework that provides strong controls to protect sensitive data, associated processes, policies, and systems in this new IT resource environment. It was with this goal in mind that the American Institute of Certified Public Accountants (AICPA) developed the SOC 2 security framework to protect the interests of their clients. Unlike other frameworks, SOC 2 is specifically designed for technology and cloud computing companies that provide outsourcing services. In this blog, we’ll provide an overview of SOC 2 and related topics.
What does SOC 2 Stand for and why was it Developed?
SOC 2 stands for Systems and Organization Controls 2. It was developed as organizations began changing how and where they stored and processed sensitive data. Throughout the early 2000’s as more and more businesses moved customer and other key stakeholders’ data to the cloud, the need to quantify the efficacy of these entities’ security protocols increased. AICPA took notice of this evolution and created the SOC2 security framework, a voluntary compliance standard that specifies how entities manage and store data extending that focus to related systems, processes, and associated policies.
The Deep Roots of SOC 1, SOC 2, and SOC 3
The forerunner and roots of SOC 2 begins more than 50 years ago to the early 1970s. At that time, the AIPCA released their first guidelines, the Statement on Auditing Standards (SAS 1) which formally outlined an independent auditor’s roles and responsibilities. Over the intervening decades, updated versions of SAS were rolled out up to SAS 70. By the 1990s, SAS 70 was used to assess the effectiveness of an organization’s internal financial controls which later grew to encompass reporting and data security more broadly.
This brings us up to the “great cloud migration” by businesses alluded to previously that culminated with the April 2010 announcement by the AIPCA of a new auditing standard titled Statement on Standards for Attestation Engagement (SSAE 16) followed by SSAE 18 in May 2017. Under SSAE 16 (and then SSAE 18), the AIPCA released three new reports:
- SOC 1: Internal controls for financial statements and reporting
- SOC 2: Internal controls for the five Trust Services Criteria (TSCs) (which will be described below)
- SOC 3: SOC 2 results, tailored for a public audience
The remainder of this blog will focus on SOC 2.
How does the SOC 2 Security Framework Align with Compliance, Audit, and Reports?
SOC 2 is a security framework. A SOC 2 audit is the process by which and organization validates they are compliant with the SOC 2 requirements. To obtain a SOC 2 report, an entity must submit to a third-party auditor (either a CPA firm or an organization certified by the AIPCA) to assess their IT security practices which quantifies they have met the SOC 2 compliance criteria. At the conclusion of the SOC 2 audit, the report issued outlines whether in the auditor’s opinion the organization security posture satisfies SOC 2 security standards. An opinion that does so will aid the SaaS or service entity in proving their data centers and cloud infrastructure controls meet SOC 2 requirements.
What are the Two Types of SOC 2 Reports?
The two types of SOC 2 reports have a similar structure:
- Overview of the entities system, controls, and processes as they relate to specific TSC with controls tied to a TSC
- Description of said controls and how they function in order to operate as designed
- Management assertion that summarizes how the entity’s controls and systems meet control objectives
There are two types of SOC 2 reports:
- Type I – Audit for a single point in time
- Type II – Audits controls over an extended period of time
It is important to note that a SOC 2 report is tailored to the unique needs of each entity. Therefore, depending on its specific business practices, each entity can design controls that follow one or more principles of trust.
What are the Details of the Five Trust Services Criteria (TSCs)?
The framework on which SOC 2 compliance is built includes the five TSCs, which together layout the critical areas of security and protection of sensitive data:

- Security: Protects information and systems against vulnerabilities and unauthorized access
- Availability: Ensures systems remain operational and meet performance requirements so stakeholder can do their work
- Processing Integrity: Verifies that data processing functions as intended and is complete, accurate, and timely
- Confidentiality: Protect sensitive data by ensuring it is restricted to authorized personnel only
- Privacy: Safeguards and manages personal data in compliance with relevant regulations and against unauthorized users
Security is the only TSC required for every report. Additional criteria are optional based on the services you provide to your customers.
What is the Common Criteria (or CC-series)?
It is another name for the Security Criteria and breakouts into nine subcategories:
- CC1 – Control environment: Does the organization value integrity and security?
- CC2 – Communication and Information: Are policies and procedures in place to ensure security? Are they communicated well to both internal and external partners?
- CC3 – Risk Assessment: Does the organization analyze risk and monitor how changes impact that risk?
- CC4 – Monitoring Controls: Does the organization monitor, evaluate, and communicate the effectiveness of its controls?
- CC5 – Control Activities: Are the proper controls, processes, and technologies in place to reduce risk?
- CC6 – Logical and Physical Access Controls: Does the organization encrypt data? Does it control who can access data and restrict physical access to servers?
- CC7 – System Operations: Are systems monitored to ensure they function properly? Are incident response and disaster recovery plans in place?
- CC8 – Change Management: Are material changes to systems properly tested and approved beforehand?
- CC9 – Risk Mitigation: Does the organization mitigate risk through proper business processes and vendor management?

The Importance and Advantages of SOC 2 Compliance?

Ultimately, showing compliance with SOC 2 requirements indicates adherence to a high level of information security. Strict compliance requirements (tested through on-site audits) can help ensure sensitive information is handled responsibly. In the process, it can:
- Enhanced Security Posture: Reduces the risk of data breaches
- Customer Trust and Marketability: Demonstrates a commitment to data protection
- Competitive Advantage: Differentiates the company from non-compliant competitors
- Regulatory Alignment: Supports compliance with other data security laws like GDPR, among many others
This can translate into:
- Improved brand reputation
- Growth in customer and prospect interest
- Time Savings, improves the bottom line
In Summary
SOC 2 compliance is part of a larger effort to protect sensitive data that resides on or is processed by third-party organizations. As businesses outsourced more and more of this activity, it became clear that the creation of an independent means developed by the AICPA of validating these third parties had effective controls in place to satisfy the five Trust Services Criteria (TSCs) would be valuable to all key stakeholders. The proliferation of SOC 2 compliance and acceptance is testament of its value.

