SOC 2
What is SOC 2?
An AICPA audit report based on the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The most common assurance report for technology service providers.
Related terms
Frameworks that govern soc 2
What the standards actually require on soc 2
Requirements naming soc 2 across 6 standards, quoted from the control text.
STAR Attestation, developed in collaboration with the AICPA, is a third-party attestation that combines a SOC 2 examination with the CCM criteria, performed by a licensed CPA firm.
STAR-L2-02 · STAR Attestation (SOC 2 + CCM) →Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...
IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral →SOC 2 engagements apply AT-C 205 examination standards to controls relevant to the Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy.
SSAE-06 · SOC 2 Engagements (AT-C 205 with TSC) →FISMA coordination with industry security frameworks. NIST CSF 2.0 (February 2024): voluntary framework + 6 functions (Govern + Identify + Protect + Detect + Respond + Recover);
FISMA-Coord-NIST-CSF-ISO27001-SOC2 · Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks →FTC Safeguards Rule crosswalk to comprehensive cybersecurity + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (Qualified Individual + Board reporting + program governance) + IDENTIFY (314.4(b) risk assessment + 314.4(c)(2) data inventory) + PROTECT (314.4(c)...
FTC-Safeguards-Crosswalk-NIST-ISO-SOC · Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2 →HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encr...
HBNR-Crosswalk-NIST-CSF-ISO-HIPAA · Crosswalk to NIST CSF 2.0, NIST 800-66, ISO 27001/27701, SOC 2 and HIPAA →Questions people ask about soc 2
What is SOC 2?
Why is SOC 2 important for compliance?
What concepts are related to SOC 2?
Which compliance frameworks address SOC 2?
Where can I learn more about SOC 2?
See how SOC 2 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.