SOC 2 is an attestation, not a certification. A licensed CPA firm examines management's description of a system together with the controls supporting it, and issues an opinion under the AICPA attestation standards. The deliverable is a report that a customer reads for its scope, its period, and its exceptions — not a certificate that hangs on a wall — and the opinion itself can be unmodified, qualified, adverse, or disclaimed.
The framework is built from the Trust Services Criteria. Security is mandatory and is expressed through nine common criteria series, CC1 to CC9, covering the control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation. Availability, processing integrity, confidentiality, and privacy are elective, added when the organisation's service commitments make them relevant.
The distinction between Type I and Type II decides the value of the report. A Type I assesses whether controls are suitably designed at a single point in time. A Type II assesses whether they also operated effectively across a period, commonly three to twelve months. Enterprise buyers generally mean Type II, and the consequence is structural: evidence has to exist throughout the observation window, so it cannot be assembled retrospectively once the auditor arrives.
Because each report covers a scope the organisation defines itself, two SOC 2 reports are not directly comparable until the system description is read. That is also why SOC 2 and ISO 27001 coexist in European procurement rather than replacing each other: the underlying control work overlaps substantially, but one produces an accredited certificate against a fixed standard and the other produces a practitioner's opinion on a self-defined scope, including any exceptions found.