THREAT-WATCH logo

THREAT‑WATCH

Glossary

SOC 2

An audit framework and report attesting that a service organization's controls meet defined trust criteria: security, availability, confidentiality, and privacy.

SOC 2 is issued by an independent auditor following AICPA's Trust Services Criteria, commonly requested by enterprise customers evaluating a vendor's security posture before signing a contract. A Type I report assesses controls at a point in time; a Type II report assesses their operating effectiveness over a period (usually 6-12 months), which most enterprise buyers require.