Overview
SOC 2 is a widely adopted standard developed by the AICPA to provide organizations with a structured framework for managing controls related to security, availability, processing integrity, confidentiality, and privacy. This framework is particularly relevant for service organizations that require transparency about their systems and processes. It uses the 2017 Trust Services Criteria (updated with revised points of focus in 2022) as its foundation and includes guidance on effective implementation and reporting. SOC 2 reports are targeted at stakeholders who need assurance about a service provider's internal controls regarding handling sensitive data. The framework also serves as the basis for a consistent and standardized examination, including illustrative examples and criteria for system descriptions.