SOC 2

How to describe the service, dependencies, customer responsibilities, and boundaries that make a SOC 2 report useful in procurement.

Start with the service promise

The AICPA's SOC 2 description criteria are used to prepare and evaluate management's description of a service organization's system. Start with the customer-facing service: the product and functions supplied, the commitments made to customers, the major processing steps, and the information the service receives, stores, or returns. Then name the infrastructure, software, people, procedures, and data involved in delivering that service.

Test the draft against a real contract or product order. If the buyer purchases one hosted product, a description of a different product or only the corporate IT environment will not answer its assurance question. If a platform has multiple versions or regional deployments, identify which are included. The goal is a boundary a reader can trace, not an exhaustive list of every asset the company owns.

Show dependencies and control ownership

Most services depend on cloud hosting, identity services, support tools, or specialist vendors. Record which dependencies affect the scoped service and how the provider oversees them. The CPA firm can advise how a material subservice organization should be presented in the report. Do not imply that a provider's SOC 2 examination directly tested every control operated by an outsourced platform.

Also identify responsibilities that remain with customers, such as configuring access, approving users, protecting their own endpoints, or sending lawful data. A buyer needs to know which controls it must operate for the combined system to meet the intended criteria. The precise presentation of these responsibilities belongs in the report developed with the CPA firm; the readiness task is to identify and document them clearly.

Connect description, criteria, and evidence

The Trust Services Criteria address Security, Availability, Processing Integrity, Confidentiality, and Privacy. Select applicable criteria with the independent CPA firm based on service commitments and the information needs of intended users. Avoid adding criteria solely to make the report appear broader. The description, control design, and evidence have to tell the same story: what the service promises, what could go wrong, which controls address that risk, and how operation will be demonstrated.

For each significant service promise, trace one example. If the description says production changes are authorized, follow a release from request through approval, deployment, and review. If it says suppliers are monitored, identify the review decision and exception follow-up. A contradiction between the prose and actual workflow is a scope problem to resolve before the examination, not a copy-editing issue.

Keep regional duties in the right place

For a European service, map GDPR roles, processor terms, and transfers on their own merits. For an Australian service, determine which Australian Privacy Principles apply. For a Singapore service, examine PDPA duties such as protection and transfer limitation. These rules can influence contractual commitments and control design, but a SOC 2 description does not by itself establish legal compliance.

Maintain a separate legal and contractual register linked to the relevant service boundary. That makes it easier to answer a cross-border buyer without claiming that a US-origin assurance report replaces local privacy analysis. Review the description whenever architecture, hosting, suppliers, products, or material customer commitments change.

Put it into practice

  • Describe the actual contracted service, including regional versions and material dependencies.
  • Mark which controls the provider, subservice organizations, and customers operate.
  • Trace commitments to selected criteria, controls, and sample evidence.
  • Review the boundary with an independent CPA firm and update it after material change.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources