All Frameworks

Compliance Framework

SOC 2 Trust Services Criteria

The industry-standard audit framework for technology and cloud service providers to demonstrate operational security and trustworthiness to customers.

5 Trust Service Categories
AICPA / Licensed CPA Firms

Overview

SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA based on five Trust Services Criteria. Unlike prescriptive standards, SOC 2 is principles-based — organizations design their own controls to satisfy each criterion, then an independent CPA firm validates effectiveness. Type I reports assess design at a point in time; Type II reports evaluate operational effectiveness over a period (typically 6–12 months). SOC 2 reports are increasingly table-stakes for B2B SaaS sales.

Who Needs This?

  • SaaS and cloud service providers
  • Technology companies handling customer data
  • Managed service and hosting providers
  • FinTech and InsurTech platforms
  • Any B2B company facing enterprise procurement security reviews

Key Benefits

  • Accelerate enterprise sales cycles with a current SOC 2 report
  • Demonstrate security posture to customers and investors
  • Identify and remediate control gaps before they become incidents
  • Build a culture of continuous security monitoring
  • Reduce time spent on security questionnaires

Key Domains

Security (CC Series)

The common criteria — required for every SOC 2 audit. Covers logical and physical access, system operations, change management, and risk mitigation.

Availability (A Series)

System uptime and performance commitments. Addresses disaster recovery, business continuity, and incident response.

Processing Integrity (PI Series)

Ensures system processing is complete, valid, accurate, timely, and authorized.

Confidentiality (C Series)

Protection of information designated as confidential. Covers encryption, access restrictions, and data disposal.

Privacy (P Series)

Collection, use, retention, disclosure, and disposal of personal information in accordance with commitments and criteria.

Related Frameworks

Need Help With SOC 2?

Our team can assess your current posture, identify gaps, and build a roadmap to compliance. Get expert guidance tailored to your organization.

Request a Compliance Assessment