✳ US · SOC 2

SOC 2: report literacy (scope and period matter; not PCI, not HIPAA, not FedRAMP)

An educational overview of SOC 2 as an AICPA attestation report on controls at a service organization for a described system. Scope, Trust Services Criteria categories, and Type I or Type II matter. Not PCI, not HIPAA, and not FedRAMP.

US · SOC 2Program explainerLast reviewed

What category of report this is

SOC 2 is part of the AICPA System and Organization Controls (SOC) suite of services. A SOC 2 examination is a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A CPA firm produces the report under AICPA professional standards. It is report literacy, not a recipe for obtaining one.

AICPA describes SOC 2 reports as intended for users who need detailed information and assurance about those controls for the systems a service organization uses to process users' data. This is not a U.S. statute, and it is not a government Authorization.

Trust Services Criteria, as category names only

The criteria family AICPA labels for these examinations is the 2017 Trust Services Criteria (With Revised Points of Focus, 2022). The categories are security, availability, processing integrity, confidentiality, and privacy. Security is the category included in a SOC 2 examination. Availability, confidentiality, processing integrity, and privacy are additional categories a report may include.

Name the categories, then stop. This page does not reprint the Trust Services Criteria, the points of focus, or a control catalog. Which categories a given report actually covers is a fact in that report, not a logo.

The described system and the period

A SOC 2 report speaks to a described system. A Type II report also speaks to a period. Open the system description boundaries, which Trust Services Criteria categories were in scope, complementary user-entity controls, carve-outs and subservice organizations, and the opinion language. A homepage shield without that scope is folklore.

How many SOC 2 reports exist is UNKNOWN on this page. A required minimum length for every Type II period is also UNKNOWN. Periods are engagement-specific. Do not treat a market habit as an Atlas rule.

Type I is not Type II

Type I is report-type literacy about the suitability of the design of controls as of a specified date. That is a point in time.

Type II is report-type literacy about the suitability of design and the operating effectiveness of controls throughout a specified period. The two types are not the same sentence. This page does not say a Type II period must be a set number of months.

An attestation report, not a seal

SOC 2 is a CPA attestation report. It is not a government license, and Atlas does not mint one. The SOC suite landing page says service organizations and CPA firms should evaluate SOC services thoroughly, and it treats promises of fast and easy engagements as a credibility risk. Prefer the report over a homepage shield. Ethics enforcement news is not this lesson.

The word SOC in a security operations center is a different term. An on-call function is not this report.

Do not invent a product report

This page does not claim that Harborline, or any named commercial product, has a SOC 2 report. Type, period, opinion, and even whether a report exists are UNKNOWN until the user entity has that report. A marketing slide is not the report.

The Technology/SaaS path still teaches Cloud Controls Matrix and CAIQ literacy. This explainer does not replace that path, and it does not invent a Harborline attestation.

Rewrite the one-line claim

Replace "they are SOC 2 certified, so we are safe, and HIPAA, PCI, and FedRAMP are done" with a reading sentence: they provided a SOC 2 report for system X, Trust Services Criteria categories Y, Type I or Type II Z, and period P. Review carve-outs, and still review tenant duties.

When a vendor sends a SOC 2 claim, privately request the report (or a bridge letter) and note the system name, the type, the period, and one carve-out question for the owner. Do not upload a real report that contains customer data into Atlas.

SOC 2 is not PCI, HIPAA, FedRAMP, or an ISO certificate

Teaching table only. It does not assign a PCI validation, a HIPAA determination, a FedRAMP Authorization, or an attestation.

Five phrases people fold into one SOC 2 logo. Not a report, and not a seal.
FolkloreLiteracy
SOC 2 means PCI is donePCI DSS is payment-brand and acquirer validation for payment account data. Different category. Atlas card: /learn/explainers/pci-dss/.
SOC 2 means HIPAA is doneThe HIPAA Security Rule is a U.S. health regime for ePHI. Different category. Atlas card: /learn/explainers/hipaa-security-rule/.
SOC 2 means FedRAMP AuthorizedFedRAMP is federal cloud Authorization reuse. Different program. Atlas card: /learn/explainers/fedramp/.
SOC 2 means an ISO certificateDifferent assurance families. Do not collapse the logos into one claim.
SOC 2 replaces my tenant IAM reviewThe report may inform vendor risk. The customer still reviews admin roles, OAuth grants, SSO and SCIM, and export and recovery. Technology/SaaS path: /learn/industries/technology-saas/.

Claims to retire

SOC 2 is a certificate that replaces PCI, HIPAA, FedRAMP, and ISO.

SOC 2 is an AICPA attestation report for a described system. PCI DSS, the HIPAA Security Rule, FedRAMP, and an ISO certificate are different regimes. A logo does not merge them.

Type I and Type II mean the same thing.

Type I addresses design as of a specified date. Type II addresses design and operating effectiveness over a specified period.

A homepage SOC 2 badge is enough. Scope, period, and carve-outs can wait.

Read the system description, the categories in scope, the type, the period, complementary user-entity controls, and carve-outs or subservice organizations. The shield is not the report.

SOC 2 means customers can skip tenant IAM, OAuth, and admin-role review.

A report may inform vendor risk. The customer still owns admin roles, OAuth grants, SSO and SCIM, and export and recovery in the tenant.

Atlas, or a SaaS marketing page, can issue a SOC 2.

A CPA firm produces a SOC 2 report. Atlas does not issue SOC 2 reports or seals. Finishing this lesson is not an attestation.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.