SOC 2 (System and Organization Controls 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). An independent CPA firm evaluates a service organisation’s controls against the Trust Services Criteria — Security, and optionally Availability, Processing Integrity, Confidentiality, and Privacy — and issues a report on how well those controls are designed and operating.
There are two report types. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report — the one most enterprise buyers ask for — assesses whether controls operated effectively over a period, typically three to twelve months. Type II therefore requires continuous evidence that controls actually ran throughout the audit window.
SOC 2 has become a de facto trust signal for B2B SaaS and cloud vendors. A clean report is frequently a prerequisite for closing enterprise deals, because it gives buyers independent assurance without having to audit every supplier themselves.
Comply automates this — see the SOC 2 framework page.