SOC 2 is an attestation, not a certification.
We bought this domain to tell you that. SOC 2 is an examination engagement performed by a licensed CPA firm under the AICPA attestation standards. It ends in an opinion. Nobody issues a certificate, because there is nobody to issue one.
A SOC 2 Report is an attestation, not a certification.
An independent CPA firm examines your controls and issues an opinion. Four possible outcomes. That opinion can be unmodified, qualified, adverse, or a disclaimer. The value is in the document, so somebody on your side should be reading it.
What are the differences between a certification and an attestation?
Both are legitimate. Neither one is the other.
A certification says somebody concluded you conform. A report hands you the opinion, the controls, and how they were tested.
| Attribute | Certificationfor example, ISO/IEC 27001 | Attestation reportfor example, SOC 2 |
|---|---|---|
| Who issues it | A certification body, itself accredited to ISO/IEC 17021-1. | An independent CPA firm, licensed by a state board of accountancy. |
| Under what rules | The standard, plus the body's certification scheme. | The American Institute of Certified Public Accountants (AICPA) attestation standards, AT-C 105 and 205, against the Trust Services Criteria. |
| What you receive | A certificate. One page, a number, a scope, an expiry date. | A report. Commonly 40 to 100+ pages: the system described, the controls, and how they were tested. |
| What it concludes | Conformity with the standard. | An opinion on management's description and on the controls. |
| Possible outcomes | Certified, or not certified. | Four, not two. Unmodified, qualified, or adverse. Or the auditor disclaims, which means declining to give an opinion at all. |
| Can you see the work | No. The audit file stays with the body. | Not the working papers. But you get management's system description, the controls, the auditor's procedures and the results. |
Scroll the table sideways →
Why not just make it a certification?
Because a CPA license is the stronger thing to put behind it.
A certification spreads accountability across a scheme and an accreditation body. An attestation concentrates it: one named CPA firm signs, with its license and its legal liability at stake.
Attest is a legal term. The Uniform Accountancy Act defines it to include SOC 2 examinations, and every state reserves that work to licensed CPA firms. The license brings ethics, independence and peer review with it, and an examination obtains reasonable assurance: the same level a financial statement audit opinion carries.
What’s in the report?
The opinion Section 1
The auditor’s opinion. Unmodified, qualified, adverse, or a disclaimer.
Management’s assertion Section 2
The company stating in writing that its description is accurate and its controls did what it says. Signed by them, not by the auditor.
The system description Section 3
The longest section, and the one worth your time. Management writes it and the auditor tests whether it is fairly presented. It sets the boundaries of what was examined: the system, what was in scope, what was carved out, and what you are expected to run on your own end. Two companies can hand you a SOC 2 and be describing completely different systems. This section tells you which one you’re holding.
The controls, the tests, and the results Section 4
The meat. Each control in management’s own words, the test the auditor performed, and what happened. Exceptions live here, in the results, not in a tidy list at the back. This is a Type 2 section: a Type 1 has no tests of operating effectiveness to report, and so has no Section 4 to read.
Everything else Section 5
Supplemental material from management. Not covered by the opinion, and the auditor says so in writing.
Numbering is conventional, not mandated. The first two sometimes trade places.
Who can issue one?
The report is signed in the firm's name. That is what puts a licensed, independent, peer reviewed professional on the hook for it.
- Licensed A firm permit from a state board of accountancy. Signed by the firm, not by an individual.
- Independent In fact and in appearance. A firm that designed your controls cannot examine them.
- Peer reviewed Enrolled in a peer review program. Another firm examines its working papers.
- Competent AT-C 105 requires it. A CPA license is necessary and, alone, not sufficient.
Cannot issue one
- Your GRC platform
- Your pen test vendor
- Your MSP
- Your vCISO
- Your law firm
- Your cloud provider
- The Security Operations Center down the hall
- The AICPA, which writes the rules and signs nothing
- Your very capable head of security
Every one of them can help you get ready, often faster and cheaper than alone. None of them can sign the opinion. A vendor offering to “certify” you is selling readiness. That is a real service, and a separate engagement.
What do I say instead?
Three phrases that come up constantly.
-
Said
We are SOC 2 certified.
Meant
We have a SOC 2 Type 2 report.
-
Said
Can you send over your SOC 2 certificate?
Meant
Can you send your SOC 2 Report, including Section 4?
-
Said
We are getting SOC 2 certified through our compliance platform.
Meant
The platform prepares us. A CPA firm performs the examination.
There is one badge, and it is a logo.
The AICPA licenses a “SOC for Service Organizations” logo. You may display it once you have a report. It is a trademark under license, not a certificate: no number, no scope, no expiry. If you see one, ask for the report.
Brought to you by
Sage Audits LLP is a licensed CPA firm that performs SOC 2 examinations. Partner led, fixed fee, and pedantic about exactly one word.
Educational, not professional advice. Whether an examination is right for you depends on facts this website does not know.