Public Service Announcement soc2certifications.com

SOC 2 certifications do not exist.

You have reached soc2certifications.com. We bought this domain specifically to tell you that. What exists is a SOC 2 report: an attestation examination, performed by a licensed CPA firm, that ends in a professional opinion rather than a certificate.

Part One

A certification and an attestation are different animals.

Both are performed by an outside party. Both cost money and take months. That is where the similarity stops. They are built on different standards, produce different artifacts, and answer different questions.

Attribute Certificationfor example, ISO/IEC 27001 Attestation reportfor example, SOC 2
Who issues it A certification body, itself accredited to ISO/IEC 17021-1 by a national accreditation body. An independent CPA firm, licensed by a state board of accountancy.
Under what rules The requirements of the standard, plus the certification scheme and accreditation rules the body operates under. The AICPA attestation standards, principally AT-C sections 105 and 205, against the Trust Services Criteria.
What you receive A certificate. One page, a certificate number, a scope statement, an expiry date. A report. Commonly 40 to 100+ pages, because the evidence is in it.
What it concludes Conformity. The management system meets the requirements of the standard. An opinion. The practitioner's professional judgment on management's description and on the controls.
Possible outcomes Certified, or not certified. Unmodified, qualified, adverse, or a disclaimer. Four possible opinions, not two.
Can you see the work No. The audit file stays with the certification body. You get the conclusion. Yes. Section IV lists the controls, the tests the auditor performed, and the result of each one.
How long it lasts A three year cycle, with annual surveillance audits and a recertification audit at the end. It does not expire. It covers a stated date or period, and then it simply gets older.

Scroll the table sideways →

Both are legitimate. Neither one is the other.

A certification tells you somebody concluded you conform. An attestation report hands you the auditor's opinion and the work behind it, and lets you form your own view. That is why your procurement team asks for the SOC 2 report and not a wallet card.

Part Two

So what is a SOC 2 report?

System and Organization Controls 2. A CPA firm examines a service organization's controls against the AICPA's Trust Services Criteria and reports an opinion on them. The deliverable is a bound document with five sections, and almost nobody reads past the first two.

  1. Independent Service Auditor's Report The opinion

    The only section the CPA firm actually writes and signs. Three or four pages. It names the criteria, the period covered, and the opinion. If you read one section, read this one, and read it to the end, because a modified opinion is stated plainly and is easy to skim past.

  2. Management's Assertion

    The service organization stating, in writing and in its own name, what it claims about its system and its controls. The auditor's opinion attaches to this assertion. This is the structural reason SOC 2 is an attestation: somebody asserts, and a practitioner attests.

  3. Management's Description of the System

    What the system does, where its boundaries sit, which subservice organizations are carved out or included, and which complementary user entity controls you are expected to run on your side. Skipping this is how a reader ends up relying on a control that was never in scope.

  4. Criteria, Controls, Tests and Results The evidence

    The longest section and the whole reason a report beats a certificate. Every applicable criterion, the controls mapped to it, the procedures the auditor performed, and the result of each test. Exceptions appear here, described specifically. This is what a vendor risk reviewer is being paid to read.

  5. Other Information Provided by Management Unaudited

    Optional, and explicitly outside the scope of the opinion. Management's responses to exceptions, roadmap items, business continuity narratives. Useful context. Not assured by anybody.

Type 1 and Type 2 are not levels

Type 1
Were the controls suitably designed as of a single date? A photograph. Useful when a company is new to this and needs something to show while a longer period accrues.
Type 2
Were the controls suitably designed and did they operate effectively over a period, usually three to twelve months? A film. This is the one your customers are asking for.

A Type 2 is not a “higher grade” of the same report. It answers a different and harder question, which is why it takes a period of time rather than a day.

Five categories, one of them mandatory

  • Security The common criteria. In every SOC 2, always.
  • Availability Included only if in scope.
  • Confidentiality Included only if in scope.
  • Processing Integrity Included only if in scope.
  • Privacy Included only if in scope.

A report scoped to Security alone is a complete and perfectly legitimate SOC 2. Adding categories does not make a report better, it makes it broader. Check which categories a vendor's report actually covers before you rely on it for availability commitments.

Part Three

Who is allowed to issue one.

A SOC 2 report is a CPA firm's work product, signed in the firm's name. That is not a formality: it is what puts a licensed, independent, peer reviewed professional on the hook for the opinion you are relying on.

  • Licensed A firm permit from a state board of accountancy. The report is signed by the firm, not by an individual auditor.
  • Independent Independent in fact and in appearance under the AICPA Code of Professional Conduct. A firm that designed and implemented your controls cannot then examine them.
  • Peer reviewed Enrolled in a peer review program, which means the firm's own working papers are periodically examined by another firm.
  • Competent AT-C 105 requires the practitioner to have the competence and capabilities to perform the engagement. Holding a CPA license is necessary and, on its own, not sufficient.

Cannot issue one

  • Your GRC platform
  • Your pen test vendor
  • Your MSP
  • Your vCISO
  • Your law firm
  • Your cloud provider
  • Your very capable head of security

Every one of these can help you get ready, and several of them will get you ready faster and cheaper than doing it alone. None of them can sign the opinion.

If a vendor tells you they will “certify” you, the thing they are selling is readiness work. That is a real and useful service. It is not the examination, and the examination is a separate engagement with a separate firm.

Part Four

Say this instead.

The practical half. Five phrases that come up constantly, and what each one should be.

  1. SaidWe are SOC 2 certified.

    MeantWe have a SOC 2 Type 2 report.

    Why There is no certificate and no certifying body. Naming the report, and its type, tells the other side exactly what you are offering to send them.

  2. SaidOur SOC 2 certification expires in March.

    MeantOur report covers the year ended December 31. The next examination period begins in March.

    Why Reports do not expire, they age. What matters to a reviewer is the period covered and whether a bridge letter covers the gap between then and now.

  3. SaidCan you send over your SOC 2 certificate?

    MeantCan you send your SOC 2 report, including Section IV?

    Why Asking for a certificate signals you are going to file it without reading it. Asking for Section IV signals you intend to look at the exceptions, which is the entire point of receiving a report.

  4. SaidWe passed our SOC 2 audit.

    MeantWe received an unmodified opinion.

    Why There is no pass mark. There is an opinion, and a report can contain noted exceptions while still carrying an unmodified opinion. "Passed" hides the distinction that a careful reader cares about most.

  5. SaidWe are getting SOC 2 certified through our compliance platform.

    MeantWe are using the platform to prepare, and a CPA firm to perform the examination.

    Why Two different engagements, two different parties, and only one of them can issue the report. Being precise about which is which prevents an awkward conversation in month five.

There is one badge, and it is a logo.

The AICPA licenses a “SOC for Service Organizations” logo that a service organization may display once it has a report. It is a trademark used under license, not a certificate, and it does not carry a number, a scope statement, or an expiry date. If you see one, ask for the report.

The More You Know

SOC 2 is a report. A licensed CPA firm issues it. It contains an opinion, not a grade.