- Full name
- SOC 2 — Service Organisation Controls (AICPA Trust Services Criteria)
- Region
- United States (used globally)
- Applies to
- Service organisations whose customers need assurance over the security, availability, processing integrity, confidentiality, or privacy of customer data. Common for SaaS vendors and cloud-service providers.
SOC 2 reports against the AICPA Trust Services Criteria (TSC) — five categories of which Security is always in scope. The criteria are principles-based rather than prescriptive: auditors expect the service organisation to design controls that meet the criteria and operate them over time. CC6 (Logical and Physical Access Controls) is the largest cluster of identity-relevant criteria.