Category: Security Certifications

What is SOC 2 Type 2 Certification?

SOC 2 (System and Organization Controls 2) is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA) that defines how service providers should manage and protect client data. A SOC 2 Type 2 certification is issued following an independent audit conducted by a licensed CPA firm, covering an extended period — typically six to twelve months — rather than a single point in time.

The audit evaluates controls across five trust service criteria:

  • Security — the system is protected against unauthorized access
  • Availability — the system is available for operation and use as committed
  • Processing Integrity — system processing is complete, valid, accurate, timely, and authorized
  • Confidentiality — information designated as confidential is protected as committed
  • Privacy — personal information is collected, used, retained, and disposed of in conformity with the provider’s stated privacy commitments

The AICPA sets the standards for SOC 2. Licensed CPA firms accredited by the AICPA conduct the audits. A current SOC 2 Type 2 report documents the results of that audit for the covered period.