Glossary · Australian Compliance
SOC 2
A US auditing standard for service organisations that documents how they protect customer data across five Trust Service Criteria.
Browse all definitionsIn detail
SOC 2 (Service Organisation Control 2) is a framework developed by the American Institute of CPAs (AICPA) for auditing the controls of service organisations around the five Trust Service Criteria of security, availability, processing integrity, confidentiality and privacy. A SOC 2 Type I report attests to the design of controls at a point in time. A Type II report covers the operating effectiveness of those controls over a period, typically six or twelve months. Licensed CPA firms produce SOC 2 reports following AICPA AT-C 205 standards.
Apply the definition
Want to talk through how this applies to your business?
Start with the decision in front of you. We will help map the fit.