◦ Reference · Framework

SOC 2

AICPA System and Organization Controls (SOC) 2, the US attestation standard for service organizations handling customer data. Reports cover security, availability, processing integrity, confidentiality, and privacy, with Trust Services Criteria maps. Attention is triggered by a qualified opinion on a Type II report, by an exception count that exhausts the AICPA materiality threshold, by a carved-out control the customer auditor flags, and by an off-cycle complementary-user-entity-controls (CUEC) gap that the customer cannot satisfy without internal changes.

/soc-2