# What is a SOC 2 Report?

> A System and Organization Controls 2 (SOC 2) report is an independent service-auditor report on controls at a service organization relevant to the American Institute of Certified Public Accountants' Trust Services Criteria.

- Canonical URL: https://yellowcube.eu/glossary/soc-2-report/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The examination addresses security and may address availability, processing integrity, confidentiality, or privacy according to the scope and service commitments described in the report.

Management describes its system and asserts that the description and controls meet the applicable criteria. An independent licensed CPA firm examines that assertion under applicable professional attestation standards. A Type 1 report addresses control design at a stated date; a Type 2 report also tests whether controls operated effectively throughout a stated period.

### Key points

- **Inspect coverage:** Confirm the system boundary, services, locations, selected criteria, subservice organizations, reporting period or date, and significant changes or exclusions.
- **Evaluate evidence:** Read the opinion, management assertion, system description, tests and exceptions for Type 2, complementary user-entity controls, and complementary subservice-organization controls.
- **Match the use:** Determine whether the report period, scope, criteria, auditor, and control evidence address the customer’s actual risks; request bridge evidence when material time has elapsed.
- **Important limitation:** SOC 2 is an attestation engagement, not a universal certification or guarantee that a provider is secure. Controls outside the described system, customer configurations, unselected criteria, events after the period, and undiscovered failures may remain unaddressed.

### Related terms

[SOC 1 report](<https://yellowcube.eu/glossary/soc-1-report/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Security operations center (SOC)](<https://yellowcube.eu/glossary/security-operations-center/>) · [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/>) · [SOC 3 report](<https://yellowcube.eu/glossary/soc-3-report/>)

### Sources

[AICPA & CIMA, System and Organization Controls: SOC Suite of Services](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services) · [AICPA & CIMA, SOC 3—Trust Services Criteria for General Use](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-3)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

