Back to library
Cybersecurity · Issued by AICPA

SOC 2

SOC 2 — AICPA System and Organization Controls

SaaSAICPATrust ServicesAudit
Compare SOC 2 with

Trust Services Criteria attestation report — the de-facto US SaaS vendor security benchmark.

Built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy. Type I = point-in-time; Type II = sustained operating effectiveness over 6–12 months. Audited annually by a CPA firm.

At a glance

Complexity
Medium
Certification
Yes (audit report)
Time to implement
6–12 months
Issued by
AICPA

Fits

Industries
itbankinginsurancehealthcare
Risk types
cybercomplianceoperational
Frequently asked

Questions risk leaders ask

SOC 2 is an attestation framework issued by AICPA that evaluates service organizations against Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy).
See if it fits you

Run the Finder to get a personalised match score for SOC 2.

Made with Emergent