What Is SOC 2? A Beginner's Guide to the Framework
What SOC 2 is, who defines it, and why it became the default trust signal for SaaS companies selling to the enterprise.
7 min read
SOC 2 is a report from an independent auditor that says a company handles customer data responsibly. It is defined by the American Institute of Certified Public Accountants (AICPA), and for most SaaS companies it has become the security review's opening question: "Are you SOC 2?"
What SOC 2 Actually Is
SOC 2 stands for System and Organization Controls, type 2. It is not a certification you pass or fail, it is an attestation: a licensed CPA firm examines your controls and issues a report describing what they found. That distinction matters, because there is no central registry and no pass mark. What you hand a buyer is the auditor's report itself.
The report is organized around the Trust Services Criteria, a set of control objectives the AICPA maintains. Security is always in scope; the others are optional depending on what you promise customers.
The Five Trust Services Criteria
- Security (required): protecting systems and data against unauthorized access.
- Availability: the system is up and reachable as committed.
- Confidentiality: information marked confidential stays that way.
- Processing integrity: the system processes data completely and accurately.
- Privacy: personal information is collected, used, and retained as disclosed.
Most first reports scope to Security alone, then add criteria as customers ask for them.
Type 1 vs Type 2
A Type 1 report checks that your controls are designed correctly on a single date. A Type 2 report checks that they operated effectively over a period, usually three to twelve months. Enterprise buyers almost always want Type 2. For the full comparison, see SOC 2 Type 1 vs Type 2.
Who Needs SOC 2
If you sell software to other businesses and touch their data, someone will eventually ask for your SOC 2 report. It is rarely a legal requirement; it is a commercial one, gating deals rather than compliance. The earlier you start, the less it holds up a specific contract.
How Concord Fits
Concord Trust gives you a control library, framework mapping, and a public trust center where buyers can request your report under NDA, plus scoped, read-only access for your auditor. It is one place to build the program and prove it, without stitching tools together.