SOC 2

The attestation enterprise buyers ask for: your controls, tested by an auditor, over a period.

Universal core · SOC 2 (AICPA Trust Services Criteria, 2017)

Issued by

AICPA

Region

International

Effective

Trust Services Criteria 2017, with 2022 points of focus

Oversight

Attested by licensed CPA firms under AICPA standards

Applies when

Service organisations whose customers ask for independent assurance

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

SOC 2 is not a certificate you hold; it is an attestation report an independent auditor writes about your controls against the Trust Services Criteria: security always, plus availability, confidentiality, processing integrity and privacy where you include them.

A Type II report covers a period, which means the evidence has to exist continuously, not just the week before fieldwork. That is what makes SOC 2 a system-of-record problem rather than a documentation sprint.

Where programmes are tested.

01

The common criteria

Control environment, communication, risk assessment, monitoring and logical access, the CC series every report includes.

02

Evidence over a period

Type II reports test operating effectiveness across months. Stale screenshots are exactly what fieldwork catches.

03

Vendor and subservice clarity

Which providers are carved out, which are included, and how you monitor them.

Curated once, evidenced continuously.

  • The Trust Services Criteria are curated and cross-mapped to the same controls that satisfy ISO 27001, so one implementation feeds both.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

SOC 2, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

What is the difference between SOC 2 Type I and Type II?

A Type I report describes your controls and tests their design at a point in time. A Type II report tests whether they operated effectively over a period, typically three to twelve months. Enterprise buyers almost always want Type II, which is why the evidence has to exist continuously.

Is SOC 2 a certification?

No. SOC 2 is an attestation: an independent auditor's opinion on your controls, with any exceptions noted in the report. There is no certificate and no pass or fail; a report with exceptions is still a report, and buyers read them.

Which Trust Services Criteria do we need to include?

Security (the common criteria) is always in scope. Availability, confidentiality, processing integrity and privacy are added based on what you commit to customers. Most SaaS reports cover security plus availability and confidentiality.

How often does a SOC 2 report need to be renewed?

Type II reports are typically issued annually, each covering a fresh period. Between reports, buyers ask for a bridge letter confirming controls have not materially changed since the last period ended.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.