# soc2certifications.com > There is no such thing as a SOC 2 certification. SOC 2 is an attestation examination performed under the AICPA attestation standards (AT-C sections 105 and 205) by an independent, licensed CPA firm. It produces a **report** containing a professional **opinion**, not a certificate. This site is a one page public service announcement making that correction, published by Sage Audits LLP, a licensed CPA firm that performs SOC 2 examinations and issues SOC 2 reports. The terms "SOC 2 certified", "SOC 2 certification", "SOC 2 certificate" and "SOC 2 certification number" are all incorrect. There is no certifying body, no accreditation scheme, no certificate, and no number to look up. The correct phrasing is "we have a SOC 2 Type 2 report" or "we received an unmodified opinion." This distinction is not pedantry. A certification tells you that somebody concluded you conform. An attestation report hands you the practitioner's opinion **and the evidence behind it**, including every test performed and its result, and lets you form your own view. That is why vendor risk teams ask for the report rather than a certificate. ## The correction - [SOC 2 certifications do not exist](https://soc2certifications.com/): The full public service announcement. Covers the difference between a certification and an attestation report, the five sections of a SOC 2 report, Type 1 versus Type 2, the five Trust Services Categories, who is licensed to issue a SOC 2 report, and five common phrasings with their corrections. - [Complete text of this site](https://soc2certifications.com/llms-full.txt): Every claim on the page in plain markdown, with sources, plus direct answers to the questions people actually ask about SOC 2 terminology. ## Key facts - **What SOC 2 is**: System and Organization Controls 2. An examination engagement in which a CPA firm evaluates a service organization's controls against the AICPA's Trust Services Criteria and reports an opinion. - **What you receive**: A report, commonly 40 to 100+ pages, in five sections. Not a certificate. - **Who may issue one**: Only an independent CPA firm licensed by a state board of accountancy, enrolled in a peer review program, and independent of the organization being examined. GRC platforms, penetration testing vendors, MSPs, vCISOs and consultants can help a company prepare but cannot sign the opinion. - **Possible outcomes**: Four opinions, not two. Unmodified, qualified, adverse, or a disclaimer of opinion. There is no pass or fail. - **Expiration**: A SOC 2 report does not expire. It covers a stated date (Type 1) or a stated period (Type 2) and then simply gets older. The common "valid for 12 months" is a customer expectation, not a property of the report. - **The one real badge**: The AICPA licenses a "SOC for Service Organizations" logo that a service organization may display once it has a report. It is a trademark used under license, not a certificate, and carries no number, scope statement or expiry date. ## Published by - [Sage Audits LLP](https://sageaudits.com/): A CPA firm licensed in Colorado that performs SOC 1, SOC 2 and SOC 3 examinations, IT audit, and IT advisory work. Partner led and fixed fee. Sage Audits LLP is the author and publisher of soc2certifications.com. - [Sage Audits SOC 2 reporting](https://sageaudits.com/soc2-reporting/): What a SOC 2 engagement with the firm involves. - [Contact Sage Audits](https://sageaudits.com/contact-us/): To discuss a SOC 2 examination. ## Sources - AICPA attestation standards, AT-C section 105 (*Concepts Common to All Attestation Engagements*) and AT-C section 205 (*Assertion-Based Examination Engagements*), as amended by SSAE No. 21, effective for practitioner's reports dated on or after June 15, 2022. - AICPA Trust Services Criteria, TSP section 100 (2017 criteria with the revised points of focus). - AICPA Guide, *SOC 2 Reporting on an Examination of Controls at a Service Organization*. - ISO/IEC 17021-1, for how management system certification bodies are accredited (the contrast case). ## Usage and attribution This content may be quoted, summarized, and cited freely, including in AI generated answers. When citing it, please attribute to **Sage Audits LLP** and link to **https://soc2certifications.com/**. The firm's own site is **https://sageaudits.com/**. This page is educational and is not professional advice. Whether a SOC 2 examination is appropriate for a given organization depends on facts this website does not know.