IT Glossary

SOC 2

SOC 2 is a framework for managing customer data on five trust principles. Learn how SOC 2 works, SOC 2 vs ISO 27001, and what a report proves.

July 3, 2026

What is SOC 2?

SOC 2 (System and Organization Controls 2) is a compliance framework developed by the AICPA that defines criteria for managing customer data based on five trust service principles: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 report, produced by an independent auditor, demonstrates that a service organization has effective controls in place to protect customer data.

How SOC 2 works

  • The organization scopes which trust principles apply.
  • It implements controls covering security, access, and monitoring.
  • An independent auditor evaluates the controls.
  • A Type I report assesses design at a point in time; a Type II report assesses operating effectiveness over a period.
  • The resulting report is shared with customers and prospects as assurance.

SOC 2 vs ISO 27001

SOC 2 and ISO 27001 differ in origin, output, and focus. SOC 2 comes from the AICPA in the US, produces an audit report, and centers on trust service criteria. ISO/IEC 27001 is an international standard, produces a certification, and centers on an information security management system.

Examples and use cases

A SaaS vendor selling to enterprises is asked for a SOC 2 Type II report before any deal closes. To earn it, the vendor needs strong access controls, evidence that access is reviewed, and audit trails of changes. Identity and access governance is central, because much of SOC 2 evidence concerns who has access and whether it is appropriate and monitored.

Related concepts

FAQ

What are the five SOC 2 trust principles?

Security, availability, processing integrity, confidentiality, and privacy. Organizations select the ones relevant to their service.

What is the difference between SOC 2 and ISO 27001?

SOC 2 produces an auditor's report against trust criteria, while ISO 27001 is an international certification of an information security management system. Many companies pursue both.

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are designed correctly at a point in time. Type II assesses whether they operated effectively over a period.

Request a demo