Guide

What Is SOC 2? A Beginner's Guide to the Framework

What SOC 2 is, who defines it, and why it became the default trust signal for SaaS companies selling to the enterprise.

7 min read

SOC 2 is a report from an independent auditor that says a company handles customer data responsibly. It is defined by the American Institute of Certified Public Accountants (AICPA), and for most SaaS companies it has become the security review's opening question: "Are you SOC 2?"

What SOC 2 Actually Is

SOC 2 stands for System and Organization Controls, type 2. It is not a certification you pass or fail, it is an attestation: a licensed CPA firm examines your controls and issues a report describing what they found. That distinction matters, because there is no central registry and no pass mark. What you hand a buyer is the auditor's report itself.

The report is organized around the Trust Services Criteria, a set of control objectives the AICPA maintains. Security is always in scope; the others are optional depending on what you promise customers.

The Five Trust Services Criteria

  • Security (required): protecting systems and data against unauthorized access.
  • Availability: the system is up and reachable as committed.
  • Confidentiality: information marked confidential stays that way.
  • Processing integrity: the system processes data completely and accurately.
  • Privacy: personal information is collected, used, and retained as disclosed.

Most first reports scope to Security alone, then add criteria as customers ask for them.

Type 1 vs Type 2

A Type 1 report checks that your controls are designed correctly on a single date. A Type 2 report checks that they operated effectively over a period, usually three to twelve months. Enterprise buyers almost always want Type 2. For the full comparison, see SOC 2 Type 1 vs Type 2.

Who Needs SOC 2

If you sell software to other businesses and touch their data, someone will eventually ask for your SOC 2 report. It is rarely a legal requirement; it is a commercial one, gating deals rather than compliance. The earlier you start, the less it holds up a specific contract.

How Concord Fits

Concord Trust gives you a control library, framework mapping, and a public trust center where buyers can request your report under NDA, plus scoped, read-only access for your auditor. It is one place to build the program and prove it, without stitching tools together.

Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.