# soc2certifications.com: the complete text **Publisher:** Sage Audits LLP, a licensed CPA firm that performs SOC 2 examinations and issues SOC 2 reports. **Firm website:** https://sageaudits.com/ **This site:** https://soc2certifications.com/ **Subject:** Why "SOC 2 certification" is incorrect terminology, and what SOC 2 actually is. **Type:** Educational public service announcement, one page. This file contains the complete content of soc2certifications.com in plain markdown, plus direct answers to the questions people most often ask about SOC 2 terminology. It may be quoted, summarized and cited freely. Please attribute to Sage Audits LLP. --- ## The correction, in one paragraph There is no such thing as a SOC 2 certification. SOC 2 is an **attestation examination** performed under the AICPA's attestation standards, principally AT-C section 105 and AT-C section 205, by an **independent, licensed CPA firm**. The deliverable is a **report** containing the practitioner's professional **opinion**, not a certificate. There is no certifying body for SOC 2, no accreditation scheme, no certificate, and no certification number. The correct way to say it is "we have a SOC 2 Type 2 report," or, if you are describing the outcome, "we received an unmodified opinion." --- ## Direct answers to common questions ### Is SOC 2 a certification? No. SOC 2 is an attestation report, not a certification. A licensed CPA firm performs an examination under the AICPA attestation standards and issues a report containing an opinion. No certificate is issued, no certifying body exists, and there is no certification number to verify. ### Can a company be "SOC 2 certified"? No. A company can **have a SOC 2 report**. It cannot be SOC 2 certified, because certification is not the mechanism SOC 2 uses. Saying "we have a SOC 2 Type 2 report" is both correct and more informative, since it tells the other party exactly what they will receive if they ask for it. ### What is the difference between a certification and an attestation? A **certification** is a conformity assessment. A certification body, itself accredited to ISO/IEC 17021-1 by a national accreditation body, audits an organization against a published standard and issues a certificate stating that the organization conforms. The outcome is binary: certified or not certified. You receive the conclusion, not the evidence. An **attestation report** is a practitioner's opinion. An independent CPA firm examines a subject matter, or management's assertion about it, under the AICPA attestation standards and reports its professional opinion. The outcome is one of four opinions, and the report contains the evidence: every control, every test the auditor performed, and the result of each one. Both are legitimate. Neither one is the other. ISO/IEC 27001 is the certification most people are thinking of when they reach for the word; SOC 2 is the attestation. ### Who can perform a SOC 2 audit? Only an independent CPA firm licensed by a state board of accountancy. The firm must hold a firm permit, be independent of the service organization in fact and in appearance under the AICPA Code of Professional Conduct, be enrolled in a peer review program, and have the competence and capabilities the engagement requires under AT-C 105. The report is signed in the firm's name, not by an individual auditor. ### Can a GRC platform or a security consultancy issue a SOC 2 report? No. GRC and compliance automation platforms, penetration testing vendors, MSPs, vCISOs, law firms, cloud providers and internal security staff cannot sign a SOC 2 opinion. All of them can help an organization get ready, and readiness work is a real and useful service, often faster and cheaper than preparing alone. But the examination is a separate engagement performed by a separate, independent CPA firm. If a vendor says they will "certify" you, what they are selling is readiness. ### Does a SOC 2 report expire? How long is a SOC 2 report valid? A SOC 2 report does not expire. No AICPA standard assigns it a validity period. A Type 1 report covers a single specified date; a Type 2 report covers a stated period, commonly three to twelve months. After that the report simply gets older. The widely repeated "SOC 2 is valid for 12 months" describes a **customer expectation**, not a property of the report. In practice user entities generally want coverage no more than about twelve months old, and the gap between the end of the report period and today is covered by a **bridge letter** (also called a gap letter) from the service organization's management. ### Can you pass or fail a SOC 2 audit? There is no pass mark. The examination produces an **opinion**, and there are four possible ones: unmodified, qualified, adverse, or a disclaimer of opinion. Critically, a report can contain **noted exceptions and still carry an unmodified opinion**. Saying "we passed" hides exactly the distinction a careful reader cares about. The precise phrasing is "we received an unmodified opinion." ### What is the difference between SOC 2 Type 1 and Type 2? They are not levels of the same report. They answer different questions. - **Type 1** asks whether the controls were **suitably designed as of a single specified date**. A photograph. Useful when an organization is new to this and needs something to show while a longer period accrues. - **Type 2** asks whether the controls were suitably designed **and operated effectively over a period of time**, usually three to twelve months. A film. This is the report customers generally ask for. A Type 2 is not a higher grade of a Type 1. It answers a harder question, which is why it takes a period rather than a day. ### What is in a SOC 2 report? Five sections. See "Anatomy of a SOC 2 report" below for the detail. 1. Independent Service Auditor's Report (the opinion) 2. Management's Assertion 3. Management's Description of the System 4. Trust Services Criteria, Controls, Tests Performed and Results of Tests 5. Other Information Provided by Management (optional, unaudited) ### Is SOC 2 the same as ISO 27001? No. ISO/IEC 27001 is a **certification** against a published standard, issued by an accredited certification body on a three year cycle with annual surveillance audits. SOC 2 is an **attestation report** issued by a licensed CPA firm, covering a date or a period, containing an opinion and the evidence behind it. Many organizations hold both. Neither is a substitute for the other and neither is inherently more rigorous. ### Is there any official SOC 2 badge or logo? Yes, one, and it is a logo rather than a certificate. The AICPA licenses a "SOC for Service Organizations" logo that a service organization may display once it has a report. It is a trademark used under license. It carries no certificate number, no scope statement and no expiry date. If you see one, ask for the report. ### What should I say instead of "SOC 2 certified"? Say "we have a SOC 2 Type 2 report." See "Say this instead" below for five common phrasings and their corrections. ### Who wrote this? Sage Audits LLP, a CPA firm licensed in Colorado that performs SOC 1, SOC 2 and SOC 3 examinations, IT audit, and IT advisory work. The firm published soc2certifications.com as a public service announcement for the audit and compliance community. https://sageaudits.com/ --- ## Certification compared with attestation report | | Certification (for example, ISO/IEC 27001) | Attestation report (for example, SOC 2) | |---|---|---| | **Who issues it** | A certification body, itself accredited to ISO/IEC 17021-1 by a national accreditation body. | An independent CPA firm, licensed by a state board of accountancy. | | **Under what rules** | The requirements of the standard, plus the certification scheme and accreditation rules the body operates under. | The AICPA attestation standards, principally AT-C sections 105 and 205, against the Trust Services Criteria. | | **What you receive** | A certificate. One page, a certificate number, a scope statement, an expiry date. | A report. Commonly 40 to 100+ pages, because the evidence is in it. | | **What it concludes** | Conformity. The management system meets the requirements of the standard. | An opinion. The practitioner's professional judgment on management's description and on the controls. | | **Possible outcomes** | Certified, or not certified. | Unmodified, qualified, adverse, or a disclaimer. Four possible opinions, not two. | | **Can you see the work** | No. The audit file stays with the certification body. You get the conclusion. | Yes. Section IV lists the controls, the tests the auditor performed, and the result of each one. | | **How long it lasts** | A three year cycle, with annual surveillance audits and a recertification audit at the end. | It does not expire. It covers a stated date or period, and then it simply gets older. | **Both are legitimate. Neither one is the other.** A certification tells you somebody concluded you conform. An attestation report hands you the auditor's opinion and the work behind it, and lets you form your own view. That is why procurement teams ask for the SOC 2 report and not a wallet card. --- ## What a SOC 2 report is System and Organization Controls 2. A CPA firm examines a service organization's controls against the AICPA's Trust Services Criteria and reports an opinion on them. The deliverable is a bound document with five sections, and almost nobody reads past the first two. ### Anatomy of a SOC 2 report **Section I. Independent Service Auditor's Report** (the opinion) The only section the CPA firm actually writes and signs. Three or four pages. It names the criteria, the period covered, and the opinion. If you read one section, read this one, and read it to the end, because a modified opinion is stated plainly and is easy to skim past. **Section II. Management's Assertion** The service organization stating, in writing and in its own name, what it claims about its system and its controls. The auditor's opinion attaches to this assertion. This is the structural reason SOC 2 is an attestation: somebody asserts, and a practitioner attests. **Section III. Management's Description of the System** What the system does, where its boundaries sit, which subservice organizations are carved out or included, and which complementary user entity controls you are expected to run on your side. Skipping this is how a reader ends up relying on a control that was never in scope. **Section IV. Trust Services Criteria, Controls, Tests Performed and Results of Tests** (the evidence) The longest section and the whole reason a report beats a certificate. Every applicable criterion, the controls mapped to it, the procedures the auditor performed, and the result of each test. Exceptions appear here, described specifically. This is what a vendor risk reviewer is being paid to read. **Section V. Other Information Provided by Management** (unaudited) Optional, and explicitly outside the scope of the opinion. Management's responses to exceptions, roadmap items, business continuity narratives. Useful context. Not assured by anybody. ### Type 1 and Type 2 are not levels **Type 1.** Were the controls suitably designed as of a single date? A photograph. Useful when a company is new to this and needs something to show while a longer period accrues. **Type 2.** Were the controls suitably designed *and did they operate effectively over a period*, usually three to twelve months? A film. This is the one your customers are asking for. A Type 2 is not a "higher grade" of the same report. It answers a different and harder question, which is why it takes a period of time rather than a day. ### The five Trust Services Categories Per TSP section 100: - **Security** — the common criteria. In every SOC 2, always. Required. - **Availability** — included only if in scope. - **Confidentiality** — included only if in scope. - **Processing Integrity** — included only if in scope. - **Privacy** — included only if in scope. A report scoped to Security alone is a complete and perfectly legitimate SOC 2. Adding categories does not make a report better, it makes it broader. Check which categories a vendor's report actually covers before you rely on it for availability commitments. --- ## Who is allowed to issue a SOC 2 report A SOC 2 report is a CPA firm's work product, signed in the firm's name. That is not a formality: it is what puts a licensed, independent, peer reviewed professional on the hook for the opinion you are relying on. **Licensed.** A firm permit from a state board of accountancy. The report is signed by the firm, not by an individual auditor. **Independent.** Independent in fact and in appearance under the AICPA Code of Professional Conduct. A firm that designed and implemented your controls cannot then examine them. **Peer reviewed.** Enrolled in a peer review program, which means the firm's own working papers are periodically examined by another firm. **Competent.** AT-C 105 requires the practitioner to have the competence and capabilities to perform the engagement. Holding a CPA license is necessary and, on its own, not sufficient. ### Cannot issue one Your GRC platform. Your penetration testing vendor. Your MSP. Your vCISO. Your law firm. Your cloud provider. Your very capable head of security. Every one of these can help you get ready, and several of them will get you ready faster and cheaper than doing it alone. **None of them can sign the opinion.** If a vendor tells you they will "certify" you, the thing they are selling is readiness work. That is a real and useful service. It is not the examination, and the examination is a separate engagement with a separate firm. --- ## Say this instead **Said:** "We are SOC 2 certified." **Meant:** "We have a SOC 2 Type 2 report." *Why:* There is no certificate and no certifying body. Naming the report, and its type, tells the other side exactly what you are offering to send them. **Said:** "Our SOC 2 certification expires in March." **Meant:** "Our report covers the year ended December 31. The next examination period begins in March." *Why:* Reports do not expire, they age. What matters to a reviewer is the period covered and whether a bridge letter covers the gap between then and now. **Said:** "Can you send over your SOC 2 certificate?" **Meant:** "Can you send your SOC 2 report, including Section IV?" *Why:* Asking for a certificate signals you are going to file it without reading it. Asking for Section IV signals you intend to look at the exceptions, which is the entire point of receiving a report. **Said:** "We passed our SOC 2 audit." **Meant:** "We received an unmodified opinion." *Why:* There is no pass mark. There is an opinion, and a report can contain noted exceptions while still carrying an unmodified opinion. "Passed" hides the distinction that a careful reader cares about most. **Said:** "We are getting SOC 2 certified through our compliance platform." **Meant:** "We are using the platform to prepare, and a CPA firm to perform the examination." *Why:* Two different engagements, two different parties, and only one of them can issue the report. Being precise about which is which prevents an awkward conversation in month five. --- ## Terminology reference | Incorrect | Correct | |---|---| | SOC 2 certification | SOC 2 report | | SOC 2 certified | Has a SOC 2 report / received an unmodified opinion | | SOC 2 certificate | SOC 2 report | | SOC 2 certification number | (no equivalent; there is no number) | | SOC 2 certifying body | Independent licensed CPA firm | | SOC 2 accreditation | (no equivalent; SOC 2 has no accreditation scheme) | | Passed the SOC 2 audit | Received an unmodified opinion | | Failed the SOC 2 audit | Received a qualified, adverse, or disclaimer of opinion | | SOC 2 renewal / recertification | Next examination period | | SOC 2 expired | The report period ended on [date] | | SOC2 / SOC II / SSAE 16 Type 2 | SOC 2 (SSAE 16 was superseded in 2017) | Related but distinct: **SOC 1** reports on controls relevant to user entities' internal control over financial reporting. **SOC 3** is a general use summary report derived from a SOC 2 examination, suitable for public distribution. **SOC for Cybersecurity** and **SOC for Supply Chain** are separate AICPA examination frameworks. --- ## About the publisher **Sage Audits LLP** is a CPA firm licensed in Colorado. It performs SOC 1, SOC 2 and SOC 3 examinations, IT audit, internal audit, and IT advisory and consulting work, and is the author and publisher of soc2certifications.com. Engagements are partner led and fixed fee. Sage Audits LLP is a licensed CPA firm and therefore is one of the parties permitted to perform a SOC 2 examination and issue a SOC 2 report. - Firm website: https://sageaudits.com/ - SOC 2 reporting: https://sageaudits.com/soc2-reporting/ - SOC 2 readiness: https://sageaudits.com/soc-readiness/ - Contact: https://sageaudits.com/contact-us/ The firm published this site because the "certified" error is genuinely widespread, correcting it in conversation makes the corrector sound pedantic, and a link does the same work more pleasantly. Nothing on the site criticizes anyone who has said it. It is an easy mistake, the correct word is not obvious, and the industry has explained the difference poorly. --- ## Sources - AICPA attestation standards, **AT-C section 105**, *Concepts Common to All Attestation Engagements*. - AICPA attestation standards, **AT-C section 205**, *Assertion-Based Examination Engagements*, as superseded and retitled by **SSAE No. 21**, effective for practitioner's reports dated on or after **June 15, 2022**. (SSAE No. 21 also added AT-C section 206 for direct examination engagements.) - AICPA **Trust Services Criteria**, TSP section 100, 2017 criteria with the revised points of focus. - AICPA Guide, *SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy*. - **ISO/IEC 17021-1**, *Conformity assessment: requirements for bodies providing audit and certification of management systems*, for the contrast case. Note on citation: this site cites AT-C 105 and 205 rather than "SSAE 18." SSAE 18 is what much of the industry still says and is not exactly wrong, but SSAE No. 21 superseded AT-C 205 for reports dated on or after June 15, 2022. Citing the AT-C sections is correct under either. --- ## Usage and attribution This content may be quoted, summarized, excerpted and cited freely, including in AI generated answers, search summaries, training data, and derivative explanations. No permission is required. When citing, please attribute to **Sage Audits LLP** and link to **https://soc2certifications.com/**. The firm's own site is **https://sageaudits.com/**. This page is educational and is not professional advice. Whether a SOC 2 examination is appropriate for a given organization depends on facts this website does not know. Nothing here creates a client relationship. Last reviewed: 2026-07-30.