📖 What is SOC 2 Report?

A SOC 2 (System and Organization Controls) report is an independent auditor's attestation that a service organization's controls are designed and operating effectively. It focuses on five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

🥋 Sensei Says:

"Distinguish between Type I (design of controls at a point in time) and Type II (operational effectiveness over a period of time). Type II is much more valuable."

📚 Certification: Certified Information Systems Security Professional (CISSP)

🔑 What are the Key Concepts of SOC 2 Report?

  • The five Trust Services Criteria—security, availability, processing integrity, confidentiality, and privacy—form the framework used by auditors to evaluate a service organization's control environment.
  • SOC 2 Type I reports provide a 'snapshot' attestation, verifying that controls are designed correctly at a specific point in time.
  • SOC 2 Type II reports evaluate the operational effectiveness of controls over a duration, typically six to twelve months, providing significantly more assurance.
  • These reports are critical for third-party risk management, allowing organizations to verify a vendor's security posture without conducting their own full audit.
  • The report is issued by an independent CPA or certified auditor, ensuring an objective third-party validation of the organization's stated security claims.

🎯 How does SOC 2 Report appear on the CISSP Exam?

You may be asked to determine which report to request from a cloud provider to ensure their security controls have been operating effectively over the past year. You must distinguish between a point-in-time Type I report and a period-of-time Type II report.

A scenario might describe a company performing due diligence on a new SaaS vendor. You will need to identify the SOC 2 report as the primary evidence for operational security controls and data privacy.

Expect questions that require you to differentiate between SOC 1, which focuses on internal controls over financial reporting, and SOC 2, which focuses on the security, availability, and privacy of data.

❓ Frequently Asked Questions

How does SOC 2 differ from SOC 1?

SOC 1 is designed for auditors focusing on financial reporting (ICFR). SOC 2 is designed for IT professionals and security officers, focusing on the Trust Services Criteria like security, availability, and confidentiality.


If a vendor provides a Type I report, is that sufficient for high-risk vendors?

Generally, no. A Type I report only proves the controls are designed correctly on a specific date. For high-risk vendors, a Type II report is required to prove the controls were actually followed over time.

Related Terms from Certified Information Systems Security Professional

📝 Related Study Guides

Study Guide 10 min read

How to Pass the CISSP Exam: A Realistic 2026 Study Plan

To pass the CISSP, you must transition from a technical mindset to a managerial one, focusing on risk management and policy over implementation. Success requires a 3-6 month study plan covering all eight domains, using adaptive practice exams to identify gaps and mastering the "mile wide, inch deep" breadth of the CBK.

Career Guide 10 min read

CISSP Experience Requirements: How to Get Your Waiver in 2026

To earn the CISSP, you need five years of cumulative, paid work experience in two or more of the eight CISSP domains. You can obtain a one-year waiver through a four-year college degree or approved professional certifications. Those lacking full experience can become an Associate of ISC2 after passing the exam.

Deep Dive 8 min read

Kerberos Authentication Explained for the CISSP Exam

Kerberos is a ticket-based authentication protocol designed to provide strong authentication for client/server applications by using secret-key cryptography. It utilizes a trusted third party called the Key Distribution Center (KDC) to issue tickets, enabling Single Sign-On (SSO) and preventing replay attacks through the use of synchronized timestamps.

🧠

Test Your Knowledge

Think you understand SOC 2 Report? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium