What category of report this is
SOC 2 is part of the AICPA System and Organization Controls (SOC) suite of services. A SOC 2 examination is a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A CPA firm produces the report under AICPA professional standards. It is report literacy, not a recipe for obtaining one.
AICPA describes SOC 2 reports as intended for users who need detailed information and assurance about those controls for the systems a service organization uses to process users' data. This is not a U.S. statute, and it is not a government Authorization.
Trust Services Criteria, as category names only
The criteria family AICPA labels for these examinations is the 2017 Trust Services Criteria (With Revised Points of Focus, 2022). The categories are security, availability, processing integrity, confidentiality, and privacy. Security is the category included in a SOC 2 examination. Availability, confidentiality, processing integrity, and privacy are additional categories a report may include.
Name the categories, then stop. This page does not reprint the Trust Services Criteria, the points of focus, or a control catalog. Which categories a given report actually covers is a fact in that report, not a logo.
The described system and the period
A SOC 2 report speaks to a described system. A Type II report also speaks to a period. Open the system description boundaries, which Trust Services Criteria categories were in scope, complementary user-entity controls, carve-outs and subservice organizations, and the opinion language. A homepage shield without that scope is folklore.
How many SOC 2 reports exist is UNKNOWN on this page. A required minimum length for every Type II period is also UNKNOWN. Periods are engagement-specific. Do not treat a market habit as an Atlas rule.
Type I is not Type II
Type I is report-type literacy about the suitability of the design of controls as of a specified date. That is a point in time.
Type II is report-type literacy about the suitability of design and the operating effectiveness of controls throughout a specified period. The two types are not the same sentence. This page does not say a Type II period must be a set number of months.
An attestation report, not a seal
SOC 2 is a CPA attestation report. It is not a government license, and Atlas does not mint one. The SOC suite landing page says service organizations and CPA firms should evaluate SOC services thoroughly, and it treats promises of fast and easy engagements as a credibility risk. Prefer the report over a homepage shield. Ethics enforcement news is not this lesson.
The word SOC in a security operations center is a different term. An on-call function is not this report.
Do not invent a product report
This page does not claim that Harborline, or any named commercial product, has a SOC 2 report. Type, period, opinion, and even whether a report exists are UNKNOWN until the user entity has that report. A marketing slide is not the report.
The Technology/SaaS path still teaches Cloud Controls Matrix and CAIQ literacy. This explainer does not replace that path, and it does not invent a Harborline attestation.
Rewrite the one-line claim
Replace "they are SOC 2 certified, so we are safe, and HIPAA, PCI, and FedRAMP are done" with a reading sentence: they provided a SOC 2 report for system X, Trust Services Criteria categories Y, Type I or Type II Z, and period P. Review carve-outs, and still review tenant duties.
When a vendor sends a SOC 2 claim, privately request the report (or a bridge letter) and note the system name, the type, the period, and one carve-out question for the owner. Do not upload a real report that contains customer data into Atlas.
SOC 2 is not PCI, HIPAA, FedRAMP, or an ISO certificate
Teaching table only. It does not assign a PCI validation, a HIPAA determination, a FedRAMP Authorization, or an attestation.
| Folklore | Literacy |
|---|---|
| SOC 2 means PCI is done | PCI DSS is payment-brand and acquirer validation for payment account data. Different category. Atlas card: /learn/explainers/pci-dss/. |
| SOC 2 means HIPAA is done | The HIPAA Security Rule is a U.S. health regime for ePHI. Different category. Atlas card: /learn/explainers/hipaa-security-rule/. |
| SOC 2 means FedRAMP Authorized | FedRAMP is federal cloud Authorization reuse. Different program. Atlas card: /learn/explainers/fedramp/. |
| SOC 2 means an ISO certificate | Different assurance families. Do not collapse the logos into one claim. |
| SOC 2 replaces my tenant IAM review | The report may inform vendor risk. The customer still reviews admin roles, OAuth grants, SSO and SCIM, and export and recovery. Technology/SaaS path: /learn/industries/technology-saas/. |
Claims to retire
SOC 2 is a certificate that replaces PCI, HIPAA, FedRAMP, and ISO.
SOC 2 is an AICPA attestation report for a described system. PCI DSS, the HIPAA Security Rule, FedRAMP, and an ISO certificate are different regimes. A logo does not merge them.
Type I and Type II mean the same thing.
Type I addresses design as of a specified date. Type II addresses design and operating effectiveness over a specified period.
A homepage SOC 2 badge is enough. Scope, period, and carve-outs can wait.
Read the system description, the categories in scope, the type, the period, complementary user-entity controls, and carve-outs or subservice organizations. The shield is not the report.
SOC 2 means customers can skip tenant IAM, OAuth, and admin-role review.
A report may inform vendor risk. The customer still owns admin roles, OAuth grants, SSO and SCIM, and export and recovery in the tenant.
Atlas, or a SaaS marketing page, can issue a SOC 2.
A CPA firm produces a SOC 2 report. Atlas does not issue SOC 2 reports or seals. Finishing this lesson is not an attestation.
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- Technology/SaaS industry path
- Customer configuration and recovery (tenant duties remain)
- PCI DSS explainer (payment account data, different regime)
- HIPAA Security Rule explainer (ePHI, different regime)
- FedRAMP explainer (cloud Authorization, different regime)
- Cloud and SaaS shared responsibility (customer duty)
- SOC (the operations center, not this report)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.