Skip to content
Glossary
Audit

SOC 2

An AICPA attestation report on the controls a service organisation uses to protect customer data.

SOC 2 (System and Organization Controls 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). An independent CPA firm evaluates a service organisation’s controls against the Trust Services Criteria — Security, and optionally Availability, Processing Integrity, Confidentiality, and Privacy — and issues a report on how well those controls are designed and operating.

There are two report types. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report — the one most enterprise buyers ask for — assesses whether controls operated effectively over a period, typically three to twelve months. Type II therefore requires continuous evidence that controls actually ran throughout the audit window.

SOC 2 has become a de facto trust signal for B2B SaaS and cloud vendors. A clean report is frequently a prerequisite for closing enterprise deals, because it gives buyers independent assurance without having to audit every supplier themselves.

Comply automates this — see the SOC 2 framework page.

See your compliance prove itself

Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.

Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.