SOC 2
SOC 2 is a US auditing standard that assesses the security controls of service providers against the Trust Services Criteria.
SOC 2 is an auditing standard from the US organisation AICPA for service providers that process customer data. An independent auditor assesses whether the controls for security and other criteria are suitable and effective.
How it works
SOC 2 is based on the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is always mandatory, while the other criteria are optional. A Type I report assesses the design of controls on a specific date. A Type II report also tests their effectiveness over a period, usually three to twelve months. The result is an audit report, not a certificate.
A practical example: a Swiss software provider wants to sell to US companies. Their procurement departments require a SOC 2 Type II report. The provider's ISO 27001 certificate is acknowledged but does not replace the report. The provider prepares for one year and then begins the first audit period.
What to look out for
- SOC 2 is mainly relevant if you have or want to attract customers in the USA.
- Select the criteria that are appropriate for your services.
- Plan the preparation and audit period realistically, often over a year.
- Use overlaps with ISO 27001 to reduce effort.
- When reviewing suppliers, read the full report, especially the exceptions.
Relevance for Swiss companies
For the Swiss market, ISO 27001 is usually the more common framework. SOC 2 is important mainly for SaaS providers and service providers with US customers. International corporations may also request the report from their suppliers.
How it differs from ISO 27001
ISO 27001 certifies a management system. SOC 2 audits specific controls and their effectiveness, describing the result in a report. Many controls overlap.
Relevance for the SOC
Several criteria relate to monitoring, detection, and incident response. A SOC provides evidence for these, such as cases, reports, and metrics.
How we implement it
Our SOC reports provide evidence for controls related to monitoring and incident response. The audit itself is performed by an independent auditor.