← All terms

SOC 2

SOC 2 is an audit framework for how service organizations protect customer data. What the Trust Services Criteria cover and where the human layer fits.

SOC 2 (System and Organization Controls 2) is an audit framework developed by the AICPA, the US body governing certified public accountants, for evaluating how a service organization protects the data it handles for customers. A SOC 2 report is produced by an independent CPA firm and assesses controls against the Trust Services Criteria: security (mandatory), plus availability, processing integrity, confidentiality and privacy as optional scopes. For SaaS companies selling to enterprises, a SOC 2 report has become the de facto entry ticket to procurement — many buyers will not sign without one.

How it works

There are two report types. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report — the one enterprise buyers usually demand — tests whether those controls actually operated effectively over an observation window, typically 3 to 12 months. The auditor collects evidence for each control: access reviews, change-management records, incident logs, vendor assessments and, notably, proof that the workforce is trained. Unlike ISO 27001, SOC 2 does not issue a certificate against a fixed standard; it produces an attestation report describing your controls and any exceptions the auditor found, which customers read and judge for themselves. Organizations that also handle card payments face a third, more prescriptive regime in PCI DSS, whose Requirement 12.6 spells out the awareness program SOC 2 only implies.

How to defend against it — and pass it

SOC 2's security criteria lean heavily on the control environment: personnel are expected to understand their security responsibilities, and auditors routinely sample evidence of onboarding and recurring security awareness training, phishing simulation results, and disciplinary or remediation processes for policy violations. Gaps in the human layer surface as exceptions in the report — visible to every prospect who reads it.

The practical approach is to run the program you would want anyway and let the audit collect the receipts: continuous security awareness training with completion tracking, regular phishing simulations with documented follow-up for repeat failures, and metrics that show the program works — the approach covered in our guide to measuring simulation programs beyond the click rate. Evidence that exists as a by-product of a real program is cheaper and more convincing than evidence manufactured in the month before the audit window closes.

Related terms

ISO 27001ISO/IEC 27001 is the international standard for information security management systems — and it makes security awareness a required, auditable control.PCI DSSPCI DSS is the security standard for organizations handling card payments. Requirement 12.6 makes ongoing security awareness training mandatory.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.Cyber HygieneCyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo