Skip to content

SOC 2 Basics

 

Learn about SOC 2, is it legally required, certification, SOC 1 & SOC 3, what SOC 2 does not cover and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization. 

Table of Contents

What is SOC 2? 

 

SOC 2, System and Organization Controls 2, is a compliance framework developed by the American Institute of Certified Public Accountants (AICPA) that defines how service organizations manage and protect customer data, verified through examination by an independent licensed CPA. 

The framework is structured around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. An independent CPA examines the organization’s controls against those criteria and issues a SOC 2 Report, the independently verified evidence of the organization’s security posture, shared under non-disclosure agreement with customers and partners who request it as part of vendor due diligence. 

SOC 2 is not a government mandate. Its commercial weight comes from enterprise, healthcare, and financial sector buyers who require a current SOC 2 Report as a vendor eligibility condition, making it functionally essential for any service organization selling into those markets.

 

Is SOC 2 a certification? 

 

SOC 2 is not a certification, no certificate is issued and no certifying body exists. The correct term is a SOC 2 Attestation, the independent auditor’s professional opinion on the design and/or effectiveness of an organization’s security controls. The output of the process is a SOC 2 Report, not a credential. The accurate statement when representing compliance status is: “We have undergone a SOC 2 examination and hold a current SOC 2 Report.” The phrase “SOC 2 certified” is widespread colloquial shorthand, even among compliance professionals, because the examination is rigorous and independently conducted. In any legal, contractual, or procurement context where precision matters, SOC 2 is an attestation, not a certification. 

 

Is SOC 2 legally required? 

 

SOC 2 is a voluntary standard with no government mandate and no statutory penalties for non-compliance. It sits in a different category than HIPAA, GDPR, or CCPA, all of which carry legal consequences. What makes SOC 2 functionally non-negotiable for many organizations is commercial pressure, not regulation. Enterprise buyers, healthcare systems, financial institutions, and regulated-sector clients routinely include a current SOC 2 Report as a vendor eligibility requirement in procurement. Without one, organizations are disqualified before commercial conversations begin. 

 

What does SOC 2 NOT cover? 

 

A SOC 2 Report attests that controls are suitably designed and operating effectively to reduce risk, it does not guarantee zero breaches, cover every system in the organization, or replace HIPAA, GDPR, or CCPA. 

SOC 2 covers only the systems within the defined scope boundary agreed upon before the examination. It does not extend to customer organizations’ own security practices, those responsibilities are documented separately as Complementary User Entity Controls (CUECs). It does not evaluate product quality or marketing claims. If a sub-processor is excluded via the carve-out method, their controls are explicitly not evaluated. If a cloud provider is carved out, the application layer, configurations, and data management remain entirely the organization’s responsibility.

 

What is SOC 1 and when does it apply instead of SOC 2? 

 

SOC 1 evaluates internal controls over financial reporting (ICFR) and applies to organizations whose services directly affect how clients account for or report their finances, payroll processors, benefits administrators, transfer agents, claims processors, and financial data custodians. SOC 2 evaluates security, privacy, and operational controls for the broad range of technology and service organizations managing customer data. The two frameworks address entirely different control sets and serve different audiences. A SaaS company that processes transactions but does not affect client financial reporting typically needs SOC 2, not SOC 1. Some organizations, payroll platforms that also store sensitive employee data, need both. 

 

What is SOC 3 and when is it used? 

 

SOC 3 uses the same five Trust Services Criteria as SOC 2 but produces a publicly distributable general-use summary without the sensitive technical detail found in a SOC 2 Report. Organizations use SOC 3 as a public-facing compliance signal, suitable for a website, marketing materials, or sales collateral without NDA requirements. SOC 3 does not contain the control descriptions, test results, or exception details that enterprise buyers need for substantive vendor due diligence. It complements a SOC 2 Report but is not a substitute when a customer requires the actual report. Organizations typically hold both: SOC 2 for customers requiring substantive review, SOC 3 for public-facing assurance. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data
Sam-IT-Solutions Logo
SAM IT Solutions

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties