The examination addresses security and may address availability, processing integrity, confidentiality, or privacy according to the scope and service commitments described in the report.
Management describes its system and asserts that the description and controls meet the applicable criteria. An independent licensed CPA firm examines that assertion under applicable professional attestation standards. A Type 1 report addresses control design at a stated date; a Type 2 report also tests whether controls operated effectively throughout a stated period.
Key points
Inspect coverageConfirm the system boundary, services, locations, selected criteria, subservice organizations, reporting period or date, and significant changes or exclusions.
Evaluate evidenceRead the opinion, management assertion, system description, tests and exceptions for Type 2, complementary user-entity controls, and complementary subservice-organization controls.
Match the useDetermine whether the report period, scope, criteria, auditor, and control evidence address the customer’s actual risks; request bridge evidence when material time has elapsed.
Important limitationSOC 2 is an attestation engagement, not a universal certification or guarantee that a provider is secure. Controls outside the described system, customer configurations, unselected criteria, events after the period, and undiscovered failures may remain unaddressed.