An attestation report on controls relevant to security, availability, processing integrity, confidentiality and privacy, prepared by an independent CPA firm.
Technology and service providers whose customers need assurance about the controls protecting data those customers entrust to them. It is the report most commonly requested by buyers in the United States.
SOC 2 is an attestation rather than a certification, and the distinction matters commercially. A Type I report addresses control design at a point in time, and a Type II report addresses operating effectiveness across a period, usually between three and twelve months. Because a Type II tests a period, preparation is dominated by evidence discipline: the controls must be running, and their operation must be demonstrable for every month of the window.
A report containing the opinion of an independent CPA firm. It is restricted-use and is shared under agreement rather than published. The opinion is the auditor's, not ours.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.