SOC 2

Definition

SOC 2 is an audit report on how a service organisation manages security, availability, processing integrity, confidentiality and privacy.

A Type I report assesses whether controls are designed correctly at a point in time; Type II assesses whether they operated effectively over a period, usually six to twelve months. It is an audit, not a certification, and a vendor that is "working toward SOC 2" has not got one.