What is SOC 2? The Trust Services Criteria and the report, explained
A plain-English guide to SOC 2: what the report actually is, the five Trust Services Criteria, why Security is the only mandatory one, and how a SOC 2 differs from a certification.

If you sell software or services to businesses, especially in North America, you'll eventually be asked for your SOC 2. It has become the default answer to a buyer's real question: can I trust you with our data? But SOC 2 is widely misunderstood, starting with the belief that it's a certification you pass. It isn't.
What SOC 2 actually is
SOC 2 stands for System and Organization Controls 2. It's an attestation report, produced by an independent CPA firm, on how well a service organisation's controls meet a defined set of criteria. The framework comes from the AICPA (the American Institute of Certified Public Accountants), which published the current Trust Services Criteria in 2017 and refreshed the underlying points of focus in 2022.
The crucial distinction: there is no such thing as a "SOC 2 certificate." No one issues you a badge that says certified. Instead, the auditor examines your controls and writes a formal opinion on whether they are suitably designed and, in a Type II, operating effectively. The deliverable is a report, not a pass mark, and it's usually shared with prospects under NDA rather than published.
That's the first mental shift for teams coming from a certification world like ISO 27001: SOC 2 is an auditor telling your customers, in detail, what you do and whether it holds up, rather than a certificate confirming you cleared a bar.
The five Trust Services Criteria
A SOC 2 is scoped against up to five Trust Services Criteria (TSC) categories. You don't have to include all of them:
- Security: protection against unauthorised access, disclosure and damage. Also called the Common Criteria, this is the backbone of every SOC 2 and the only mandatory category.
- Availability: that the system is available for operation and use as committed.
- Processing integrity: that processing is complete, valid, accurate, timely and authorised.
- Confidentiality: that information designated as confidential is protected.
- Privacy: that personal information is collected, used, retained and disposed of in line with your commitments.
Security is always in scope. You add the other four based on two things: what you actually commit to customers, and what your buyers ask for. A payments platform will usually add Availability and Processing Integrity; a business handling health or consumer data might add Confidentiality and Privacy. Adding a category you can't evidence just gives the auditor more to find, so most organisations start with Security alone and expand deliberately.
Underneath the Security category sit the Common Criteria, CC1 to CC9: control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation. If that list feels familiar, it's because it maps closely to the kind of controls an ISO 27001 Statement of Applicability already covers.
What's actually in the report
A SOC 2 report is a substantial document, typically running to dozens of pages. It contains:
- Management's assertion: your own statement about your system and the controls in place.
- The independent auditor's report: the CPA firm's opinion.
- The system description: a detailed narrative of the service, its boundaries, and the controls.
- The description of tests and results (Type II only), for each control, what the auditor tested and what they found, including any exceptions.
Because the report exposes real detail about how you operate, it's a restricted-use document. You share it with customers and prospects under an NDA, not on your website. If you want something public-facing, that's what a SOC 3 is for, which we cover in SOC 1 vs SOC 2 vs SOC 3.
Type I or Type II?
Every SOC 2 is either a Type I or a Type II. In short, a Type I looks at whether your controls are well designed at a single point in time, while a Type II also tests whether they operated effectively over a period of months. Type II is what enterprise and regulated buyers expect. The choice matters enough that we've given it its own guide: SOC 2 Type I vs Type II.
Who needs one, and why
SOC 2 is the trust currency of North American B2B. If your buyers are US enterprises, their security and procurement teams will treat a current SOC 2 Type II as table stakes, the thing that lets you clear vendor review without a hundred-question spreadsheet. Internationally, ISO 27001 plays a similar role, which is why plenty of companies pursue both and reuse most of the same controls and evidence across them.
The work behind a SOC 2 isn't the audit; it's running the controls well all year so the evidence is there when the auditor asks. ResiliencePilot manages that continuously, mapping one set of controls and evidence to SOC 2, ISO 27001 and the frameworks alongside them. See the SOC 2 solution, browse the SOC 2 hub, or book a demo.