SOC 2 · Trust Services Criteria · type I and II
Your provider’s report also states what you must do yourself.
SOC 2 is the customary assurance report for providers in the Anglo-Saxon world. For you as a customer it is an audit report to read and assess – not a seal.
A SOC 2 report is produced by an audit firm and assesses a provider’s controls against the Trust Services Criteria. Type I looks at design at a point in time, type II adds operating effectiveness across a period, usually six to twelve months.
Two elements decide its value for you: how sub-service organisations are handled, either included or expressly carved out, and the complementary user entity controls. A report with many carve-outs covers considerably less than the cover suggests.
What to check in the report
- Type and audit period – a type I says nothing about effectiveness over time.
- Which criteria were examined: security alone, or availability, confidentiality and privacy too.
- How sub-service organisations were treated: included or carved out.
- Exceptions identified and their impact.
- The list of controls that sit with the customer.
What the customer must do with it
- Obtain
- Request the report, not merely confirmation that one exists.
- Read
- Assess period, scope and exceptions and record the outcome.
- Implement
- Run the complementary user entity controls as your own tasks.
- Close gaps
- Assess carved-out sub-service organisations separately.
- Renew
- Reports cover a period – request the next before it lapses.
How SCRM covers it
Report with period
Type, audit period and criteria as fields rather than a filename.
Customer controls as tasks
What sits with you gets an owner and a date.
Carved-out parties
A separate entry in the dependency graph, so the gap stays visible.
Renewal on a cycle
The next report is requested before the current one ages out.
Frequently asked
Is SOC 2 comparable to ISO 27001?
Both concern information security but differ fundamentally: ISO 27001 certifies a management system, SOC 2 is an audit report on controls. Many providers hold both.
Does SOC 2 satisfy ISO 27001 A.5.19?
It is a strong building block but does not replace your own assessment. The evidence is that you reviewed the report and acted on it.
What does “carve-out” mean?
The sub-service organisation was excluded from the examination. You must then assess it yourself – frequently the overlooked part.