IT Glossary
SOC 2 is a framework for managing customer data on five trust principles. Learn how SOC 2 works, SOC 2 vs ISO 27001, and what a report proves.
July 3, 2026
SOC 2 (System and Organization Controls 2) is a compliance framework developed by the AICPA that defines criteria for managing customer data based on five trust service principles: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 report, produced by an independent auditor, demonstrates that a service organization has effective controls in place to protect customer data.
SOC 2 and ISO 27001 differ in origin, output, and focus. SOC 2 comes from the AICPA in the US, produces an audit report, and centers on trust service criteria. ISO/IEC 27001 is an international standard, produces a certification, and centers on an information security management system.
A SaaS vendor selling to enterprises is asked for a SOC 2 Type II report before any deal closes. To earn it, the vendor needs strong access controls, evidence that access is reviewed, and audit trails of changes. Identity and access governance is central, because much of SOC 2 evidence concerns who has access and whether it is appropriate and monitored.
Security, availability, processing integrity, confidentiality, and privacy. Organizations select the ones relevant to their service.
SOC 2 produces an auditor's report against trust criteria, while ISO 27001 is an international certification of an information security management system. Many companies pursue both.
Type I assesses whether controls are designed correctly at a point in time. Type II assesses whether they operated effectively over a period.