Skip to content

SOC 2

What is SOC 2?

An AICPA audit report based on the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The most common assurance report for technology service providers.

Audit

What the standards actually require on soc 2

Requirements naming soc 2 across 6 standards, quoted from the control text.

STAR Attestation, developed in collaboration with the AICPA, is a third-party attestation that combines a SOC 2 examination with the CCM criteria, performed by a licensed CPA firm.

STAR-L2-02 · STAR Attestation (SOC 2 + CCM)

Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...

IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral

SOC 2 engagements apply AT-C 205 examination standards to controls relevant to the Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy.

SSAE-06 · SOC 2 Engagements (AT-C 205 with TSC)
FISMA1 control

FISMA coordination with industry security frameworks. NIST CSF 2.0 (February 2024): voluntary framework + 6 functions (Govern + Identify + Protect + Detect + Respond + Recover);

FISMA-Coord-NIST-CSF-ISO27001-SOC2 · Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks

FTC Safeguards Rule crosswalk to comprehensive cybersecurity + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (Qualified Individual + Board reporting + program governance) + IDENTIFY (314.4(b) risk assessment + 314.4(c)(2) data inventory) + PROTECT (314.4(c)...

FTC-Safeguards-Crosswalk-NIST-ISO-SOC · Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2

HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encr...

HBNR-Crosswalk-NIST-CSF-ISO-HIPAA · Crosswalk to NIST CSF 2.0, NIST 800-66, ISO 27001/27701, SOC 2 and HIPAA

Questions people ask about soc 2

What is SOC 2?
An AICPA audit report based on the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The most common assurance report for technology service providers.
Why is SOC 2 important for compliance?
SOC 2 is a key concept in Audit. Understanding soc 2 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to SOC 2?
Key concepts related to SOC 2 include SOC 1, Trust Services Criteria. Understanding these interconnected concepts provides a more comprehensive view of Audit requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address SOC 2?
SOC 2 appears in the requirement text of CSA STAR (Security, Trust, Assurance, and Risk), IRS Publication 1075, SSAE 18 - Attestation Standards (SOC Reporting), FISMA, FTC GLBA Safeguards Rule (16 CFR Part 314). Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about SOC 2?
Explore our compliance framework pages to see how soc 2 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how SOC 2 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.