System and Organization Controls 2
AICPA (American Institute of Certified Public Accountants)
To give a service organization's customers and partners independent, CPA-audited assurance that its controls around security, availability, processing integrity, confidentiality, and privacy actually work, without each customer having to audit the vendor themselves.
SaaS companies, cloud service providers, and B2B technology vendors, especially in the US market, where a SOC 2 report is frequently a baseline procurement requirement before an enterprise customer will sign a contract.
An active, ongoing attestation standard, not a versioned document. Audits are performed as Type I (controls exist at a point in time) or Type II (controls operated effectively over a period, typically 6-12 months) against the AICPA's Trust Services Criteria.
AICPA SOC 2KloudSec, built by the team behind Toc Consulting
What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.