SOC 2 (System and Organization Controls 2) is an attestation standard from the American Institute of CPAs that evaluates how a service organization protects customer data.
It's built around five Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy — though most companies scope their report to Security plus whichever others are relevant to their product. A Type I report assesses controls at a single point in time; a Type II report assesses whether those controls operated effectively over an observation period, usually 3 to 12 months, and carries more weight with enterprise buyers.
Trust Services Criteria
AICPA
AICPA Trust Services Criteria (2017, revised 2022)