Compliance glossary
What is SOC 2?
SOC 2 (System and Organization Controls 2) is an attestation report issued by an AICPA-licensed independent auditor that evaluates an organisation's controls against the Trust Services Criteria.
In one line: SOC 2 is not a certification but an independent auditor's report on how well an organisation's controls protect customer data against the Trust Services Criteria.
Definition
SOC 2 operates under AICPA governance as an audit framework that assesses an organisation's controls across the Trust Services Criteria. The Security category is mandatory, and four further categories are optional: Availability, Processing Integrity, Confidentiality, and Privacy.
Two audit types exist. A Type 1 report assesses the design of controls at a single point in time. A Type 2 report assesses both the design and the operating effectiveness of those controls over a period, typically 6 to 12 months.
Core components
- Trust Services Criteria. The framework the auditor evaluates against, with Security mandatory and Availability, Processing Integrity, Confidentiality, and Privacy optional.
- Common Criteria (CC1 to CC9). The mandatory Security controls that every SOC 2 engagement must cover.
- Type 1 vs Type 2. Type 1 is a point-in-time assessment of control design. Type 2 adds operating effectiveness measured across an observation period.
- Audit period. The Type 2 observation window, typically 6 to 12 months.
- AICPA-licensed CPA firm. Only a licensed firm can perform the engagement and issue the report.
- Restricted-use report. The SOC 2 report is distributed under restricted use rather than published openly.
Why it matters
SOC 2 is the report North American technology buyers most often ask for during procurement and vendor due diligence. A current Type 2 report is frequently the difference between passing a security review and stalling a deal.
For MSPs and lean IT teams, SOC 2 readiness is both an internal requirement and a service they can deliver to clients who are being asked for the report by their own customers.
How Lavawall® helps with SOC 2
Lavawall® includes SOC 2 as a first-class framework. The Trust Services Criteria map to live evidence collected across Windows, macOS, and Linux endpoints and M365, Entra, Azure, and Google Workspace tenants, so the technical controls behind the Common Criteria are evidenced continuously rather than assembled in a rush before the audit.
Continuous collection shortens the Type 2 observation period from a fire drill into a steady stream of evidence. Lavawall® does not issue the report, since that requires an AICPA-licensed firm, but it provides the supporting documentation and evidence the auditor relies on, in co-branded form the MSP can deliver to the client.
Frequently asked
- Should I get a Type 1 or Type 2 report?
- Type 2 is the enterprise procurement standard, because it tests operating effectiveness over a period rather than design at a single point in time. Type 1 serves interim purposes, for example when a buyer needs early evidence while a Type 2 observation window is still running.
- How long does a SOC 2 audit take?
- A Type 2 report is period-based and the observation window typically spans 6 to 12 months. Collecting evidence continuously rather than scrambling before the audit accelerates readiness and shortens the path to a clean report.
- Do SOC 2 and ISO 27001 share evidence?
- Yes. SOC 2 and ISO 27001 controls substantially align, so a single evidence base can support both. Organisations pursuing both certifications can reuse much of the same control evidence rather than building two separate programs.
- Who can issue a SOC 2 report?
- Only an AICPA-licensed CPA firm can issue the report. Lavawall® does not issue SOC 2 reports; it provides the supporting documentation and continuous evidence that the auditor relies on.