Public Service Announcement SOC 2 Certification

SOC 2 is an attestation, not a certification.

We bought this domain to tell you that. SOC 2 is an examination engagement performed by a licensed CPA firm under the AICPA attestation standards. It ends in an opinion. Nobody issues a certificate, because there is nobody to issue one.

So What Is It?

A SOC 2 Report is an attestation, not a certification.

An independent CPA firm examines your controls and issues an opinion. Four possible outcomes. That opinion can be unmodified, qualified, adverse, or a disclaimer. The value is in the document, so somebody on your side should be reading it.

What are the differences between a certification and an attestation?

Both are legitimate. Neither one is the other.

A certification says somebody concluded you conform. A report hands you the opinion, the controls, and how they were tested.

Attribute Certificationfor example, ISO/IEC 27001 Attestation reportfor example, SOC 2
Who issues it A certification body, itself accredited to ISO/IEC 17021-1. An independent CPA firm, licensed by a state board of accountancy.
Under what rules The standard, plus the body's certification scheme. The American Institute of Certified Public Accountants (AICPA) attestation standards, AT-C 105 and 205, against the Trust Services Criteria.
What you receive A certificate. One page, a number, a scope, an expiry date. A report. Commonly 40 to 100+ pages: the system described, the controls, and how they were tested.
What it concludes Conformity with the standard. An opinion on management's description and on the controls.
Possible outcomes Certified, or not certified. Four, not two. Unmodified, qualified, or adverse. Or the auditor disclaims, which means declining to give an opinion at all.
Can you see the work No. The audit file stays with the body. Not the working papers. But you get management's system description, the controls, the auditor's procedures and the results.

Scroll the table sideways →

Why not just make it a certification?

Because a CPA license is the stronger thing to put behind it.

A certification spreads accountability across a scheme and an accreditation body. An attestation concentrates it: one named CPA firm signs, with its license and its legal liability at stake.

Attest is a legal term. The Uniform Accountancy Act defines it to include SOC 2 examinations, and every state reserves that work to licensed CPA firms. The license brings ethics, independence and peer review with it, and an examination obtains reasonable assurance: the same level a financial statement audit opinion carries.

What’s in the report?

The opinion Section 1

The auditor’s opinion. Unmodified, qualified, adverse, or a disclaimer.

Management’s assertion Section 2

The company stating in writing that its description is accurate and its controls did what it says. Signed by them, not by the auditor.

The system description Section 3

The longest section, and the one worth your time. Management writes it and the auditor tests whether it is fairly presented. It sets the boundaries of what was examined: the system, what was in scope, what was carved out, and what you are expected to run on your own end. Two companies can hand you a SOC 2 and be describing completely different systems. This section tells you which one you’re holding.

The controls, the tests, and the results Section 4

The meat. Each control in management’s own words, the test the auditor performed, and what happened. Exceptions live here, in the results, not in a tidy list at the back. This is a Type 2 section: a Type 1 has no tests of operating effectiveness to report, and so has no Section 4 to read.

Everything else Section 5

Supplemental material from management. Not covered by the opinion, and the auditor says so in writing.

Numbering is conventional, not mandated. The first two sometimes trade places.

Who can issue one?

The report is signed in the firm's name. That is what puts a licensed, independent, peer reviewed professional on the hook for it.

  • Licensed A firm permit from a state board of accountancy. Signed by the firm, not by an individual.
  • Independent In fact and in appearance. A firm that designed your controls cannot examine them.
  • Peer reviewed Enrolled in a peer review program. Another firm examines its working papers.
  • Competent AT-C 105 requires it. A CPA license is necessary and, alone, not sufficient.

Cannot issue one

  • Your GRC platform
  • Your pen test vendor
  • Your MSP
  • Your vCISO
  • Your law firm
  • Your cloud provider
  • The Security Operations Center down the hall
  • The AICPA, which writes the rules and signs nothing
  • Your very capable head of security

Every one of them can help you get ready, often faster and cheaper than alone. None of them can sign the opinion. A vendor offering to “certify” you is selling readiness. That is a real service, and a separate engagement.

What do I say instead?

Three phrases that come up constantly.

  1. SaidWe are SOC 2 certified.

    MeantWe have a SOC 2 Type 2 report.

  2. SaidCan you send over your SOC 2 certificate?

    MeantCan you send your SOC 2 Report, including Section 4?

  3. SaidWe are getting SOC 2 certified through our compliance platform.

    MeantThe platform prepares us. A CPA firm performs the examination.

There is one badge, and it is a logo.

The AICPA licenses a “SOC for Service Organizations” logo. You may display it once you have a report. It is a trademark under license, not a certificate: no number, no scope, no expiry. If you see one, ask for the report.