FRAMEWORKS

SOC 2 Trust Services Criteria

SOC 2 is an attestation framework developed by the AICPA that evaluates an organisation's controls for security, availability, processing integrity, confidentiality, and privacy against the Trust Services Criteria.

Section 01 · The attestation framework

What a SOC 2 examination produces

SOC 2 is an attestation, not a certification. A licensed CPA firm examines management's description of a system together with the controls supporting it, and issues an opinion under the AICPA attestation standards. The deliverable is a report that a customer reads for its scope, its period, and its exceptions — not a certificate that hangs on a wall — and the opinion itself can be unmodified, qualified, adverse, or disclaimed.

The framework is built from the Trust Services Criteria. Security is mandatory and is expressed through nine common criteria series, CC1 to CC9, covering the control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation. Availability, processing integrity, confidentiality, and privacy are elective, added when the organisation's service commitments make them relevant.

The distinction between Type I and Type II decides the value of the report. A Type I assesses whether controls are suitably designed at a single point in time. A Type II assesses whether they also operated effectively across a period, commonly three to twelve months. Enterprise buyers generally mean Type II, and the consequence is structural: evidence has to exist throughout the observation window, so it cannot be assembled retrospectively once the auditor arrives.

Because each report covers a scope the organisation defines itself, two SOC 2 reports are not directly comparable until the system description is read. That is also why SOC 2 and ISO 27001 coexist in European procurement rather than replacing each other: the underlying control work overlaps substantially, but one produces an accredited certificate against a fixed standard and the other produces a practitioner's opinion on a self-defined scope, including any exceptions found.

5
Trust Services categories
9
Common criteria series (CC1–CC9)
Security
The only mandatory category
3–12 mo
Typical Type II observation period
CPA firm
Who may issue the report
What the Trust Services Criteria enumerate

Readiness is measured against the published criteria rather than a private checklist. Each cell represents one entry; point at a group to see its contents. Counts are the complete sets.

Security category, mandatory in every SOC 2

9 of 23
  • CC1 Control environment
  • CC2 Communication and information
  • CC3 Risk assessment
  • CC4 Monitoring activities
  • CC5 Control activities
  • CC6 Logical and physical access controls
  • CC7 System operations
  • CC8 Change management
  • CC9 Risk mitigation
Section 02 · Readiness drivers

Why SOC 2 usually arrives from outside

Almost no organisation pursues SOC 2 because it wanted to. The report is requested by a customer — typically a US enterprise buyer whose security review will not clear without one — or by an investor during diligence, or by a prime contractor flowing the requirement down. The consequence is a deadline set by someone else, and a Type II observation period that has to start well before the date the report is needed.

  1. 01 US enterprise procurement A named requirement in the security review, where no report means the deal does not progress. Strength 5 of 5
  2. 02 Observation period pressure A Type II covers a past window, so the date evidence starts being kept decides the earliest possible report date. Strength 4 of 5
  3. 03 Investor and acquirer diligence A clean report shortens technical diligence; a qualified one invites questions about everything else. Strength 4 of 5
  4. 04 System boundary definition Scope set too wide adds cost and exceptions; set too narrow, the report fails to answer the customer's question. Strength 3 of 5
  5. 05 Existing ISO 27001 certification Much of the control work is already done, which changes the effort from building to evidencing. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
SaaS providers selling into the US

The report is the standard answer to an American security questionnaire, where ISO 27001 alone often prompts a follow-up rather than closing the review.

Subservice organisations

A provider relying on cloud or managed services must decide between the carve-out and inclusive methods, which changes what the report covers and what customers still have to verify.

Organisations already certified to ISO 27001

The control set largely transfers, but SOC 2 requires evidence of operation across a period and a system description written for an external reader.

Section 03 · How Up Secure helps

Where you will get supported

The areas we work in, and where each one falls across a SOC 2 readiness programme. The examination itself is performed by an independent CPA firm; everything before and around it is where support applies. The services that deliver them are listed further down.

Areas of support across SOC 2 readiness
SOC 2 support by readiness stage
Area of support ScopePrepareObserveReport
Advisory & leadership
Category selection and system boundary Covered during Scope Covered during Prepare Not covered during Observe Not covered during Report
Security leadership (vCISO) Covered during Scope Covered during Prepare Covered during Observe Covered during Report
Subservice and carve-out decisions Covered during Scope Covered during Prepare Not covered during Observe Not covered during Report
Assessment & assurance
Readiness assessment against the criteria Covered during Scope Covered during Prepare Not covered during Observe Not covered during Report
Risk assessment for CC3 Covered during Scope Covered during Prepare Covered during Observe Not covered during Report
Technical testing of access and change controls Not covered during Scope Covered during Prepare Covered during Observe Covered during Report
Vendor and subservice review Not covered during Scope Covered during Prepare Covered during Observe Covered during Report
Evidence & operation
Evidence collection during the observation period Not covered during Scope Covered during Prepare Covered during Observe Covered during Report
Exception handling and remediation Not covered during Scope Not covered during Prepare Covered during Observe Covered during Report
Enablement & tooling
Control owner training and handover Not covered during Scope Covered during Prepare Covered during Observe Covered during Report
Section 04 · Related services

Services supporting SOC 2 readiness

The catalogue below is selected from the live service graph and grouped by area of expertise. Readiness work and the examination must stay separate: the firm that designs and implements controls cannot also issue the opinion on them, and buyers notice when that line has been blurred.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

Web Application Penetration Testing

Web app penetration testing with OWASP methodology. Severity-scored findings and remediation guidance for Python/Django.

NIS 2 DirectiveISO 27001SOC 2
Read more

SOC 2 Compliance Services

SOC 2 compliance services — readiness assessment, controls design, evidence collection, and Type I/II audit support.

SOC 2
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

SOC 2 Compliance Services

SOC 2 compliance services — readiness assessment, controls design, evidence collection, and Type I/II audit support.

SOC 2
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

Virtual CISO (vCISO) Services

Fractional vCISO providing security strategy, risk management, and compliance oversight for growing SaaS teams.

NIS 2 DirectiveISO 27001SOC 2
Read more

Process Outsourcing and Managed Services

Ongoing risk assessments, vendor due diligence programs, and compliance monitoring delivered as managed services with defined service levels and regular reporting cadences.

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

Vendor Risk Assessment

Third-party vendor risk assessment for cybersecurity, data protection, and supply chain security compliance.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more
Start the conversation

Scope SOC 2 readiness with the observation period working in your favour.

The first conversation settles the system boundary, which Trust Services categories your service commitments actually require, and when evidence collection has to begin. A Type II covers a past window, so that start date — not the audit date — decides how soon a usable report can exist.

Why Up Secure
Readiness, not the opinion We prepare; a licensed CPA firm examines. Keeping those apart is what makes the resulting report worth showing to a customer.
Scope sized to your commitments Categories that no customer promise requires add cost and create additional controls that can fail during the period.
ISO 27001 work carried over Where you are already certified, most of the control set transfers and the effort shifts from building to evidencing operation.
Section 05 · Frequently asked

SOC 2 questions before committing to a report

Frequently asked questions

Is SOC 2 a certification?
No. It is an attestation examination performed by a licensed CPA firm, resulting in a report and an opinion rather than a certificate. There is no accreditation body, no certificate number, and no expiry date in the ISO sense. Reports cover a defined period, and customers usually expect a new one each year, often with a bridge letter covering the gap between the end of the reporting period and the date they receive it.
Type I or Type II?
A Type I evaluates whether controls are suitably designed at a single date; a Type II evaluates whether they also operated effectively across a period, typically three to twelve months. Enterprise buyers almost always mean Type II. A Type I can be useful as an interim signal while the observation window runs, but treating it as the destination usually leads to the request being repeated a few months later.
Which Trust Services categories should be included?
Security is mandatory. The other four follow from what the organisation has actually promised customers: availability where uptime commitments exist, confidentiality where customer data is held under non-disclosure terms, processing integrity where the service performs transactions or calculations on the customer's behalf, and privacy where personal information is processed. Adding categories that no commitment requires increases cost and the number of controls that can fail.
How does SOC 2 compare with ISO 27001?
They overlap heavily in substance and differ in form. ISO 27001 certifies a management system against a fixed international standard through an accredited body, on a three-year cycle with annual surveillance. SOC 2 produces a practitioner's opinion on a scope the organisation defines, for a stated period, and the report discloses any exceptions found. Most control work serves both. Organisations selling into both European and US markets frequently maintain both rather than choosing.
What is the carve-out method?
Where a service relies on subservice organisations — cloud hosting, managed infrastructure, payment processing — the report either carves them out or includes them. The carve-out method excludes the subservice organisation's controls from the scope and instead states the complementary controls the customer should expect it to have, usually evidenced by that provider's own SOC 2. The inclusive method brings them inside the examination, which requires their cooperation and is far less common.
What happens if a control fails during the period?
It becomes an exception in the report. That is normal and not automatically fatal: the report describes what was tested, what deviated, and management's response. Whether the opinion is modified depends on how material the exception is to the criteria it relates to. What damages credibility is not the exception itself but the absence of detection, of a documented response, or of evidence that the control was ever meant to operate as described.