SOC 2

Choose reporting criteria based on the service and buyer concern rather than adding categories for appearance.

Start with the user’s risk question

The AICPA Trust Services Criteria address security, availability, processing integrity, confidentiality, and privacy. Ask customers which risks they are trying to understand and what service they buy. A hosting service with uptime commitments may have a clear availability question; a service processing transactions may need a different discussion.

Security is the common foundation for SOC 2 reporting. The additional criteria should be selected with the independent CPA firm and reflected in the system description, commitments, and actual controls.

Match the criteria to commitments

Review contracts, service levels, privacy notices, product claims, and internal objectives. If availability is selected, identify the availability commitments, monitoring, capacity, backup, and recovery evidence. If confidentiality or privacy is relevant, distinguish how confidential information is protected from how personal information is collected, used, retained, and disclosed.

Do not treat a contractual promise as evidence that the promise is met. Each material commitment needs a control owner and records over the examination period.

Avoid scope that obscures the service

A criterion may be technically possible to include yet add little value for a particular buyer. Additional scope creates more controls and evidence to operate. Conversely, a narrow report can miss the reason customers requested assurance. Write a one-page rationale for each criterion and ask a sample of important buyers whether it answers their due diligence question.

Report distribution and detail also matter. A SOC 3 general-use report does not provide the same level of detail as SOC 2, according to the AICPA.

Use a readiness decision record

Record the intended report users, service, criteria, management commitments, major suppliers, and anticipated examination timing. Review the decision with the CPA firm before making public promises. Revisit it when the product or customer base changes.

A credible report is an independent examination of the described controls; readiness consulting prepares the operating environment and evidence but does not issue the report.

Put it into practice

  • Collect actual buyer questions and contractual commitments.
  • Explain why each proposed criterion is relevant to the service.
  • Confirm scope and criteria with the independent CPA firm.
  • Reassess selection when service or buyer expectations change.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources