Standard

    SOC 2

    System and Organization Controls 2

    AICPA (American Institute of Certified Public Accountants)

    Why It Exists

    To give a service organization's customers and partners independent, CPA-audited assurance that its controls around security, availability, processing integrity, confidentiality, and privacy actually work, without each customer having to audit the vendor themselves.

    Who It's For

    SaaS companies, cloud service providers, and B2B technology vendors, especially in the US market, where a SOC 2 report is frequently a baseline procurement requirement before an enterprise customer will sign a contract.

    Current Status

    An active, ongoing attestation standard, not a versioned document. Audits are performed as Type I (controls exist at a point in time) or Type II (controls operated effectively over a period, typically 6-12 months) against the AICPA's Trust Services Criteria.

    AICPA SOC 2

    Frequently Asked Questions

    KloudSec, built by the team behind Toc Consulting

    See SOC 2 checked automatically, continuously

    What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.

    Try KloudSec free