What SOC 2 actually is
SOC 2 is an attestation performed by a licensed CPA firm against the AICPA Trust Services Criteria. Security (the Common Criteria) is mandatory; availability, confidentiality, processing integrity and privacy are optional and should only be added when a buyer contractually requires them.
- There is no SOC 2 certificate — the deliverable is a report
- Scope is your system, not your whole company
- The auditor tests evidence, not intentions