Back to Frameworks
Security

SOC 2

SOC 2 (System and Organization Controls 2) is an attestation standard from the American Institute of CPAs that evaluates how a service organization protects customer data.

It's built around five Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy — though most companies scope their report to Security plus whichever others are relevant to their product. A Type I report assesses controls at a single point in time; a Type II report assesses whether those controls operated effectively over an observation period, usually 3 to 12 months, and carries more weight with enterprise buyers.

See how LumiGRC handles SOC 2

Get a Demo
5

Trust Services Criteria

0%
Typical certification profile
Audit Rigor58%
Time to Certify67%
Surveillance Burden70%
Issued & Enforced By

AICPA

AICPA Trust Services Criteria (2017, revised 2022)

Key Points

  • Issued via an independent CPA firm attestation, not a certification body
  • Five Trust Services Criteria; Security is mandatory, others are optional
  • Type I = point in time, Type II = effectiveness over a period
  • The de facto standard for US B2B SaaS security reviews