Skip to main content

FRAMEWORKS & CERTIFICATIONS

What Is SOC 2?

DEFINITION

SOC 2 is an attestation framework from the AICPA in which an independent CPA firm examines a service organization's controls against the Trust Services Criteria and issues a report. A Type I report covers control design at a point in time; a Type II report covers operating effectiveness over a period. It is the default security proof requested from B2B software and service vendors in North America.

SOC 2 is an attestation, not a certification. A licensed CPA firm evaluates the controls a company has defined against the AICPA Trust Services Criteria and issues an opinion. The criteria in use remain the 2017 Trust Services Criteria, updated with revised points of focus in September 2023; the AICPA has not issued new criteria for 2026. The security category is mandatory in every report, and availability, processing integrity, confidentiality, and privacy can be added based on customer commitments.

SOC 2 reports are requested almost universally by enterprise and mid-market buyers of B2B software and services in North America, usually during security review or vendor onboarding. For many sales processes, a current Type II report is the difference between closing and stalling.

The practical implication for a mid-market company is timeline: a Type II report requires an observation window, commonly three to twelve months, during which controls must operate consistently, so the work has to start well before a customer asks. Z Cyber's SOC 2 readiness solution covers scoping through audit support, and the SOC 2 compliance guide for 2026 explains the full process.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →