SOC 2 (System and Organization Controls 2) is a compliance standard for service organizations that replaced SAS 70 (Statement on Auditing Standards) in 2011. SOC 2 was created by the American Institute of Certified Public Accountants (AICPA).
SOC 2 specifies the criteria by which organizations should manage customer data and spells out five trust service principles or Trust Service Criteria (TSC): security, privacy, confidentiality, processing integrity and availability. Through these criteria, SOC 2 reports attest to the trustworthiness of services offered by an enterprise and result from an official audit procedure carried out by a certified public accountant.
This type of report attests to the operating effectiveness of a vendor’s systems and controls.