Skip to content

Glossary · Australian Compliance

SOC 2

A US auditing standard for service organisations that documents how they protect customer data across five Trust Service Criteria.

Browse all definitions

In detail

SOC 2 (Service Organisation Control 2) is a framework developed by the American Institute of CPAs (AICPA) for auditing the controls of service organisations around the five Trust Service Criteria of security, availability, processing integrity, confidentiality and privacy. A SOC 2 Type I report attests to the design of controls at a point in time. A Type II report covers the operating effectiveness of those controls over a period, typically six or twelve months. Licensed CPA firms produce SOC 2 reports following AICPA AT-C 205 standards.

Sources & further reading

Check the source, not just the summary

Apply the definition

Want to talk through how this applies to your business?

Start with the decision in front of you. We will help map the fit.

Straight answers · no pitch deck · no commitment