
THREAT‑WATCH
Glossary
SOC 2
An audit framework and report attesting that a service organization's controls meet defined trust criteria: security, availability, confidentiality, and privacy.
SOC 2 is issued by an independent auditor following AICPA's Trust Services Criteria, commonly requested by enterprise customers evaluating a vendor's security posture before signing a contract. A Type I report assesses controls at a point in time; a Type II report assesses their operating effectiveness over a period (usually 6-12 months), which most enterprise buyers require.