GLOSSARY · SAAS SECURITY

SOC 2

An independent auditor's report on how a service organization controls customer data, assessed against the AICPA's trust services criteria. Not a certification.

SOC 2 is a report, not a certificate and not a standard you comply with. A licensed accounting firm examines the controls you claim to operate and gives an opinion on them, measured against the trust services criteria published by the AICPA. Security is the only mandatory criterion. Availability, confidentiality, processing integrity, and privacy are added at your discretion, usually because a customer asked.

The distinction that decides cost is the report type. Type I says your controls were designed appropriately at a single point in time. Type II says they actually operated over a period, commonly three to twelve months. Buyers want Type II, because Type I proves only that you wrote the policies down.

The important consequence for a small company is that you choose the controls in scope. SOC 2 does not hand you a checklist of required measures; it holds you to the ones you described. Claiming less and doing it consistently produces a cleaner report than claiming a mature programme you cannot evidence.

It is also the single most common reason a founder’s first enterprise deal stalls, which is why it arrives on the roadmap as a sales problem rather than a security one.