FrameworkUnited StatesGlobal

SOC 2

AICPA · Version 2017 TSC · 2017 (revised Trust Services Criteria)

The AICPA attestation standard for service organizations managing customer data.

Overview

SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants under the Trust Services Criteria. It assesses controls at service organizations that affect the security, availability, processing integrity, confidentiality, and privacy of customer data. SOC 2 does not produce a certification. A licensed CPA firm examines your controls and issues an attestation report. Type I reports assess whether controls are suitably designed at a single point in time. Type II reports assess whether controls operated effectively over a minimum six-month observation period.

The Security criterion, known as the Common Criteria, is required in every SOC 2 engagement. It covers nine control categories from CC1 through CC9, addressing the COSO internal control framework as applied to information technology. The other four criteria — Availability, Processing Integrity, Confidentiality, and Privacy — are selected based on the nature of the services provided and what customers contractually require. Most SaaS vendors pursuing SOC 2 for the first time start with Security plus Confidentiality. Adding Privacy requires coverage of personal information collection, use, retention, and disposal.

Who Needs This

SaaS and cloud platforms selling to enterprise customers who require vendor security assurance

Technology companies completing enterprise security questionnaires at scale

Data processors, analytics firms, payroll providers, and managed IT services

Any vendor whose customer contracts include security attestation requirements

Startups building toward enterprise sales who need to demonstrate security maturity early

Structure at a Glance

Control environment, communication, risk assessment, monitoring activities, logical and physical access controls, system operations, and change management. Required in all SOC 2 reports.

A1Availability3 controls

Capacity management, environmental protection, and recovery infrastructure to meet availability commitments.

Complete, valid, accurate, timely, and authorized processing of transactions and data.

Identification, handling, and disposal of confidential information in accordance with commitments.

P1–P8Privacy8 controls

Personal information collection notice, choice, collection, use and retention, access, disclosure, and monitoring.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

Type II Readiness Assessment

Use this before engaging a CPA firm to assess readiness for specific criteria.

You are a SOC 2 specialist preparing a readiness assessment. My organization is a [TYPE] platform with [NUMBER] employees. We are targeting Security (CC) and [LIST ANY ADDITIONAL CRITERIA]. Evaluate the following control description for [CRITERION/CC NUMBER]: [DESCRIBE YOUR CONTROL]. Identify: specific gaps versus the Trust Services Criteria, evidence required to satisfy Type II testing, likely CPA firm testing procedures for this control, and a readiness rating of Ready, Needs Improvement, or Not Ready with clear reasoning.

Control Narrative Drafting

Use this to write system description narratives for each criterion.

Draft a SOC 2 control narrative for criterion [CC NUMBER] — [CRITERION NAME]. My organization: [DESCRIBE SYSTEM AND ENVIRONMENT]. The narrative must be written in present tense, describe the specific control activity and not just the goal, identify the control owner by job title, reference the specific evidence artifact this control produces, and be suitable for inclusion in a formal SOC 2 system description. Avoid generic language. Be specific about tooling, process steps, and cadence.

Subservice Organization Assessment

Use this when evaluating a third-party vendor for inclusion in your SOC 2 scope.

I am evaluating a subservice organization for our SOC 2 Type II report. This vendor handles [DESCRIBE FUNCTION] for our organization. They process [DESCRIBE DATA TYPE]. Provide: (1) which Trust Services Criteria their SOC 2 report should cover for this function, (2) five specific questions to ask their security team, (3) what their SOC 2 report must address regarding [SPECIFIC RISK CONCERN], and (4) whether a carve-out or inclusive method is more appropriate for this vendor relationship and why.

Exception Response Memo

Use this when a Type II report contains exceptions and you need to respond to customers.

A SOC 2 Type II report for our organization contains an exception for [DESCRIBE THE EXCEPTION]. The criterion affected is [CC NUMBER]. I need to draft a memo for customers explaining: what the exception was, why it occurred, what we have done to remediate it, what compensating controls were in place during the period, and why customer data was not materially affected. Keep the tone factual and professional. Do not be defensive. Be specific about remediation timelines.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Choosing Type I to move quickly, then facing enterprise customers who require Type II. Most enterprise procurement teams specify Type II in vendor questionnaires. Type I is often a wasted audit cycle.

2

System description that does not match what auditors observe during fieldwork. Inaccuracies between the description and observed reality can result in a qualified opinion.

3

CC6 (Logical Access) exceptions are the most common Type II finding. Access reviews must run on a documented cadence and evidence must be retained for every cycle during the audit period.

4

Underscoping the vendor management program. Every subservice organization relevant to in-scope systems must be addressed through either the carve-out or inclusive method.

5

Adding the Privacy criterion without a functioning consent management and data retention program. The AICPA P criteria require demonstrating actual operational compliance across all eight privacy categories.

Cross-Framework Mapping

ISO 27001

SOC 2 Common Criteria align substantially with ISO 27001 Annex A Technological and Organizational controls. Dual-certified organizations often consolidate evidence collection.

View Detailed Mapping ↗

HIPAA

SOC 2 Privacy criterion addresses personal information handling. Healthcare SaaS vendors typically combine SOC 2 Security with HIPAA Security Rule compliance.

View Detailed Mapping ↗

GDPR

SOC 2 Privacy criterion overlaps with several GDPR obligations around data subject rights and data retention. The two are complementary but not substitutes for each other.

All content sourced from official issuing body documentation.

Official source ↗

Framework

SOC 2