← All cheat sheets

SOC 2

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

SOC 2 (System and Organization Controls 2) is an AICPA attestation
report on a service organization's controls relevant to the Trust
Services Criteria. It is common in vendor due diligence and often
requested alongside ISO 27001. This sheet covers the report types,
the five criteria, control mapping, and the audit process.

KEY FACTS#

# Owner:     AICPA (US); performed by a licensed CPA firm
# Standard:  SSAE 18 / AT-C 105 & 205; Trust Services Criteria (TSC)
# Audience:  customers, partners (report is confidential, NDA-gated)
# Not a certification - it is an attestation REPORT with an opinion
# Contrast: ISO 27001 = certifiable ISMS standard (international)

REPORT TYPES#

# SOC 1  - controls relevant to financial reporting (ICFR) - not this
# SOC 2  - controls relevant to the Trust Services Criteria
# SOC 3  - public-facing summary of a SOC 2 (no detail, shareable)

SOC 2 TYPE I vs TYPE II#

# TYPE I  - design of controls at a POINT IN TIME
#           (are the right controls defined?)
# TYPE II - design + OPERATING EFFECTIVENESS over a PERIOD
#           (typically 3-12 months; usually 6-12)
#           (did the controls actually work over time?)
# Type II is what most customers want in vendor due diligence

TRUST SERVICES CRITERIA (TSC)#

# SECURITY (Common Criteria, CC) - MANDATORY in every SOC 2
#   protection against unauthorized access (physical + logical)
# AVAILABILITY        - system uptime / SLAs / DR
# PROCESSING INTEGRITY- complete, valid, accurate, timely processing
# CONFIDENTIALITY     - protection of confidential information
# PRIVACY             - PII collected/used/retained/disposed per notice
# You always include Security; add others based on service + customer
# commitments

COMMON CRITERIA (CC SERIES)#

# CC1  Control environment (governance, ethics, org structure)
# CC2  Communication & information
# CC3  Risk assessment
# CC4  Monitoring activities
# CC5  Control activities
# CC6  Logical & physical access controls
# CC7  System operations (incident, monitoring, detection)
# CC8  Change management
# CC9  Risk mitigation (vendor / business disruption)
# CC = the Security criterion, structured on the COSO framework

TYPICAL CONTROL AREAS (EVIDENCE)#

# - Access control: MFA, least privilege, joiner/mover/leaver, reviews
# - Change management: PR review, approvals, CI/CD gates, ticketing
# - Vulnerability mgmt: scanning cadence, patch SLAs, pen test
# - Logging & monitoring: SIEM, alerting, retention
# - Incident response: IR plan, tabletop, post-incident review
# - Vendor management: third-party risk assessments, SOC 2 of subs
# - BCP/DR: backups, restore tests, RTO/RPO
# - HR security: background checks, security training, policy sign-off

AUDIT PROCESS#

# 1. Scoping - pick TSC, define system boundary + period
# 2. Readiness assessment (gap analysis) - fix gaps before audit
# 3. Remediation - implement/operate controls (Type II needs history)
# 4. Audit fieldwork - CPA tests design + operating effectiveness
# 5. Report issuance - opinion + control matrix + test results
# 6. Annual cadence - Type II usually renewed each period

OPINION TYPES#

# Unqualified  - controls suitably designed & operating (the goal)
# Qualified    - one or more exceptions noted
# Adverse      - controls not effective
# Disclaimer   - auditor cannot form an opinion

SOC 2 vs ISO 27001 (QUICK MAP)#

# SOC 2: US-oriented, attestation report, TSC, period-based (Type II)
# ISO 27001: international, certifiable ISMS, Annex A / 2022 controls
# Heavy overlap in controls - a strong ISMS covers most of CC6-CC8;
# many orgs run both to satisfy different customers
# Neither is DORA - but both provide design evidence toward DORA ICT
# risk management (independent DORA-delta verification still required)

EXAMPLES#

# Decide TSC scope: Security (always) + Availability + Confidentiality
# Choose Type II with a 6-month initial observation period
# Map existing ISO 27001 Annex A controls to the CC series to reuse
# Stand up access reviews + change tickets early (Type II needs a trail)

NOTES#

- SOC 2 is a REPORT, not a badge - "SOC 2 certified" is a misnomer;
  say "SOC 2 Type II report with an unqualified opinion"
- Type II value comes from the observation period - controls must
  have an evidence trail across the whole window
- The report is confidential; share under NDA, or share SOC 3 publicly
- For LU FS clients, a vendor's SOC 2 Type II supports (but does not
  replace) DORA third-party due diligence and CSSF outsourcing review
- Practitioner reference, not audit or legal advice

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.