SOC 2
Universal core · SOC 2 (AICPA Trust Services Criteria, 2017)
AICPA
International
Trust Services Criteria 2017, with 2022 points of focus
Attested by licensed CPA firms under AICPA standards
Service organisations whose customers ask for independent assurance
Curated, versioned & cross-mapped
The obligation, plainly.
SOC 2 is not a certificate you hold; it is an attestation report an independent auditor writes about your controls against the Trust Services Criteria: security always, plus availability, confidentiality, processing integrity and privacy where you include them.
A Type II report covers a period, which means the evidence has to exist continuously, not just the week before fieldwork. That is what makes SOC 2 a system-of-record problem rather than a documentation sprint.
Where programmes are tested.
The common criteria
Control environment, communication, risk assessment, monitoring and logical access, the CC series every report includes.
Evidence over a period
Type II reports test operating effectiveness across months. Stale screenshots are exactly what fieldwork catches.
Vendor and subservice clarity
Which providers are carved out, which are included, and how you monitor them.
Curated once, evidenced continuously.
- The Trust Services Criteria are curated and cross-mapped to the same controls that satisfy ISO 27001, so one implementation feeds both.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
SOC 2, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
What is the difference between SOC 2 Type I and Type II?
A Type I report describes your controls and tests their design at a point in time. A Type II report tests whether they operated effectively over a period, typically three to twelve months. Enterprise buyers almost always want Type II, which is why the evidence has to exist continuously.
Is SOC 2 a certification?
No. SOC 2 is an attestation: an independent auditor's opinion on your controls, with any exceptions noted in the report. There is no certificate and no pass or fail; a report with exceptions is still a report, and buyers read them.
Which Trust Services Criteria do we need to include?
Security (the common criteria) is always in scope. Availability, confidentiality, processing integrity and privacy are added based on what you commit to customers. Most SaaS reports cover security plus availability and confidentiality.
How often does a SOC 2 report need to be renewed?
Type II reports are typically issued annually, each covering a fresh period. Between reports, buyers ask for a bridge letter confirming controls have not materially changed since the last period ended.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.