Learn about SOC 2 Certification, SOC 2 Attestation, the difference between a SOC 2 examination, a SOC 2 audit, & SOC 2 Report, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization.
Table of Contents
What is the AICPA?
The AICPA (American Institute of Certified Public Accountants) is the US professional organization responsible for developing and maintaining the SOC 2 framework, including the Trust Services Criteria (TSC) that auditors use to evaluate a company’s controls.
The AICPA’s role:
- It sets the standards, not the exams. The AICPA establishes the attestation standards (AT-C 105 and AT-C 205) that govern how SOC 2 examinations are conducted, but it doesn’t perform the examinations itself.
- It doesn’t issue certifications. There’s no such thing as being “AICPA certified” for SOC 2. The AICPA doesn’t grant credentials or certifications to companies. A SOC 2 report is an attestation, not a certificate.
- CPA authorization comes directly from the AICPA’s standards. Only Certified Public Accountants are licensed to perform attestation engagements under AICPA rules, which is why SOC 2 audits can only be conducted by a CPA, or by a CPA firm employing certified technical experts working under a CPA’s supervision. This licensing link is what gives a SOC 2 report its authority: the CPA’s credential is granted and governed by the AICPA, and that same body wrote the criteria the CPA is auditing against.
- Only licensed CPA firms can conduct SOC 2 audits. These firms must operate under AICPA attestation standards and typically hold AICPA membership in good standing to issue valid SOC 2 reports.
In short, the AICPA acts as the standard-setter and licensing authority behind SOC 2. It defines both the criteria being tested and who is authorized to test them, while independent CPA firms handle the actual audit work and issue the reports.
What are the Trust Services Criteria (TSC) in SOC 2?
The Trust Services Criteria (TSC) are the standards developed by the AICPA (American Institute of Certified Public Accountants) that auditors use to evaluate a service organization’s controls during a SOC 2 audit. They define the specific areas a company’s systems and processes must address to demonstrate that customer data is managed securely and responsibly.
There are five Trust Services Criteria:
- Security (Common Criteria): Protects systems against unauthorized access, both physical and logical. This is the only mandatory criterion for every SOC 2 report.
- Availability: Ensures systems are operational and accessible as agreed upon, covering uptime, performance monitoring, and disaster recovery.
- Processing Integrity: Confirms that system processing is complete, accurate, timely, and authorized.
- Confidentiality: Ensures information designated as confidential is protected according to policy, throughout its lifecycle.
- Privacy: Governs how personal information is collected, used, retained, disclosed, and disposed of, in line with the organization’s privacy notice.
Every SOC 2 report must include the Security criterion, since it forms the baseline for all others. Organizations then choose which additional criteria apply based on the services they provide and what’s relevant to their customers, for example, a SaaS company handling payment data might include Processing Integrity, while one handling sensitive personal data might add Privacy.
Auditors assess how well a company’s controls align with these criteria to determine SOC 2 compliance, making the TSC the foundation of the entire SOC 2 framework.
What are Points of Focus in SOC 2?
Points of Focus are illustrative guidance published by the AICPA alongside each Trust Services Criterion. They give concrete examples of how an organization might satisfy a given criterion, essentially showing auditors and companies what “good” can look like in practice.
Note:
- They’re not mandatory controls. Points of Focus are reference points, not a checklist a company must follow line by line. An organization can meet a criterion in a different way and still pass, as long as its approach achieves the same objective.
- Auditors use them as a benchmark. During an audit, they help evaluate whether a company’s control design is suitable for its specific environment, rather than forcing every business into the same rigid template.
- They add flexibility to SOC 2. Since companies vary widely in size, industry, and risk profile, Points of Focus let the framework stay adaptable while still giving everyone a shared frame of reference for what strong controls typically involve.
What is a Service Auditor in SOC 2?
A Service Auditor is the independent licensed CPA or CPA firm that performs the SOC 2 examination. Only licensed CPA firms are authorized to conduct SOC 2 examinations under AICPA attestation standards. The Service Auditor’s formal opinion letter appears in Section 1 of every SOC 2 Report.
What is SOC 2+?
SOC 2+ is an extended SOC 2 examination in which the standard Trust Services Criteria evaluation is supplemented with simultaneous testing against one or more additional compliance frameworks, such as HIPAA Security Rule, HITRUST CSF, ISO 27001, PCI DSS, NIST Cybersecurity Framework, or NIST SP 800-53, producing combined assurance in a single audit engagement. Shared controls are tested once and credited to multiple frameworks, reducing overall audit burden compared to running separate assessments.
What is a User Entity in SOC 2?
A User Entity is the customer organization that receives and relies on a service organization’s SOC 2 Report as part of its own vendor due diligence and is responsible for fulfilling any Complementary User Entity Controls (CUECs) listed in that report. A vendor’s controls alone are insufficient if the User Entity does not implement the corresponding obligations on its end, the combined security posture depends on both parties fulfilling their respective responsibilities.
What does it mean when a company says it is “SOC 2 certified”?
“SOC 2 certified” is widespread colloquial shorthand for a process that produces an attestation, not a certification, no SOC 2 certificate is issued, and no certifying body exists. The correct term is a SOC 2 Attestation, the independent auditor’s professional opinion on the design and/or effectiveness of an organization’s security controls. The output of the process is a SOC 2 Report, not a credential. The technically accurate and defensible statement is: “We hold a current SOC 2 Report reflecting an unqualified opinion from our independent auditor.” In legal, contractual, or procurement contexts requiring precision, the distinction matters, a certification implies a credential issued by an accrediting body, which SOC 2 does not produce.
What is a SOC 2 Attestation?
A SOC 2 Attestation is the professional declaration embedded in the SOC 2 Report in which an independent CPA formally states their opinion on whether an organization’s controls satisfy the applicable Trust Services Criteria. Because the AICPA sets SOC 2 standards but does not issue certificates, what organizations receive from the examination is an attestation, a sworn professional opinion, rather than a certification or credential. An unqualified opinion is the favorable attestation that customers and partners expect to see when requesting a vendor’s SOC 2 Report.
What is the difference between a SOC 2 Attestation and a SOC 2 certification?
A SOC 2 Attestation is what organizations actually hold after completing the process, a professional opinion issued by a licensed CPA about the effectiveness of their security controls. A certification, by contrast, is a formal credential issued by an accrediting body, such as ISO 27001 certification issued by an accredited certification body. SOC 2 has no certifying body and issues no credential. When enterprise buyers, legal teams, or auditors ask whether a vendor is “SOC 2 certified,” the technically correct and defensible answer is: “We hold a current SOC 2 Report reflecting an unqualified opinion from our independent auditor.”
What is the difference between a SOC 2 examination, a SOC 2 audit, and a SOC 2 Report?
The SOC 2 examination, the audit, and the report are three distinct things, the examination is the full engagement, the audit is the testing phase within it, and the report is the deliverable produced at the end. The SOC 2 examination is the entire formal engagement, governed by AICPA attestation standards, covering planning, scoping, fieldwork, testing, the Management Assertion, and report issuance. The SOC 2 audit, or audit fieldwork, is the active testing phase within the examination, during which the CPA reviews evidence, selects samples, interviews personnel, and verifies controls. The SOC 2 Report is the formal document produced at the conclusion, containing the auditor’s opinion letter, the system description, Management Assertion, and in a Type 2 Report, the detailed results of control testing across the observation period.
How does a SOC 1 engagement differ from a SOC 2 examination in scope and report structure?
SOC 1 and SOC 2 address entirely different control sets, serve different audiences, and produce reports that serve different purposes, they are not interchangeable. SOC 1 evaluates internal controls over financial reporting (ICFR) and applies to organizations whose services directly affect how clients account for or report their finances, payroll processors, benefits administrators, transfer agents, claims processors, and financial data custodians. SOC 2 evaluates security, availability, processing integrity, confidentiality, and privacy controls for the broad range of technology and service organizations managing customer data. A SaaS company processing transactions that do not affect client financial reporting typically needs SOC 2, not SOC 1. Some organizations, payroll platforms storing sensitive employee data, for example, need both.
How does a SOC 3 Report differ from a SOC 2 Report in format and distribution rights?
A SOC 3 Report uses the same five Trust Services Criteria as a SOC 2 Report but differs fundamentally in format and distribution: a SOC 2 Report is restricted-use and shared only with specified parties under NDA, while a SOC 3 Report can be published freely, on a website, in marketing materials, or in sales collateral, without NDA requirements. SOC 3 does not contain the control descriptions, test results, exception details, or system description that enterprise buyers need for substantive due diligence. It provides a public compliance signal only. Organizations typically hold both: the SOC 2 Report for customers requiring substantive review, the SOC 3 for public-facing assurance.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties