Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · SOC 2
Reference · LeakTrace Intelligence Team

SOC 2.

SOC 2 — Trust Services Criteria (AICPA)
At a glance
Jurisdiction
US Federal
Breach reporting deadline
Contractual — controlled by customer BAAs and MSAs
Applies to
AllSaasService Organizations
Authoritative source
https://www.aicpa-cima.com/topic/audit-assurance/audit-and-a…
Last updated
August 5, 2026
## What it is SOC 2 (Service Organization Control 2) is a reporting framework developed by the American Institute of Certified Public Accountants (AICPA). It is not a certification, not a law, and not enforced by any government agency — it is an independent auditor's report on a service organization's controls relevant to the Trust Services Criteria (TSC). It has become a de facto market requirement for enterprise B2B SaaS and cloud service providers. ## Who it applies to Any service organization whose services could impact user entities' financial reporting, security, or trust. Common adopters include SaaS platforms, cloud infrastructure providers, managed service providers, data processors, and any organization whose customers require independent third-party attestation of control effectiveness. ## Trust Services Criteria - **Security (Common Criteria — required):** Protection against unauthorized access (physical and logical), unauthorized disclosure, and damage to systems - **Availability:** System is available for operation and use as committed - **Processing Integrity:** System processing is complete, valid, accurate, timely, and authorized - **Confidentiality:** Information designated as confidential is protected as committed - **Privacy:** Personal information is collected, used, retained, disclosed, and disposed of in accordance with the entity's privacy notice The Security TSC is mandatory in every SOC 2 examination. The other four are optional and selected based on the service organization's commitments to user entities. ## Type 1 vs Type 2 reports - **Type 1:** Auditor's opinion on the design of controls as of a specific date. Point-in-time snapshot. - **Type 2:** Auditor's opinion on the design AND operating effectiveness of controls over a period of time (typically 6-12 months). Standard for mature vendor due diligence. Type 2 reports are what enterprise procurement teams typically require; Type 1 is often the initial step for organizations pursuing their first SOC 2. ## The Common Criteria (CC series) Under the 2017 Trust Services Criteria (revised 2022 points of focus), Security is organized into nine Common Criteria series: - **CC1 — Control Environment:** Integrity, ethics, governance, competence - **CC2 — Communication and Information:** Internal and external communication - **CC3 — Risk Assessment:** Identification and analysis of risks - **CC4 — Monitoring Activities:** Ongoing and separate evaluations - **CC5 — Control Activities:** Design and deployment of control activities - **CC6 — Logical and Physical Access Controls:** Restrict access appropriately - **CC7 — System Operations:** Detect and respond to threats - **CC8 — Change Management:** Authorize, design, develop, implement changes - **CC9 — Risk Mitigation:** Identify, select, and develop risk mitigation activities ## Breach handling within SOC 2 SOC 2 has no statutory breach-notification deadline — obligations are contractual, flowing through the Master Services Agreement (MSA), Data Processing Addendum (DPA), and any applicable Business Associate Agreement. However, CC7 controls typically require: - Documented incident response plan - Timely detection and response to security incidents - Notification of user entities per contractual commitments - Post-incident analysis and corrective action ## Auditor selection and scope SOC 2 examinations must be performed by a licensed CPA firm. The auditor selects a sample of controls to test based on materiality and risk. Report scoping — what systems, services, and time periods are covered — is negotiated between the service organization and auditor and disclosed on the report cover page. ## How LeakTrace aligns LeakTrace supports service organizations with continuous external-surface monitoring that directly maps to CC6 (logical access), CC7 (system operations / threat detection), and CC9 (risk mitigation) evidence. Documentation is prepared to slot into SOC 2 auditor evidence requests with dates, chain-of-custody, and control-linkage annotations.
Key provisions
Trust Services Criteria — Security (CC series)
Common Criteria applied in every SOC 2 examination; covers governance, risk assessment, monitoring, control activities, access controls, operations, change management, and risk mitigation.
CC6.1 — Logical and physical access
Restrict logical and physical access to protect information assets from security events.
CC6.6 — External access controls
Implement logical access security measures to protect against threats from sources outside the system boundaries.
CC7.2 — Anomaly detection
Monitor system components and the operation of controls for anomalies indicative of malicious acts, natural disasters, or errors.
CC7.4 — Incident response
Respond to identified security incidents by executing a defined incident response program.
Vendor management (CC9.2)
Assess and manage risks associated with vendors and business partners with access to information assets.
Recent amendments & guidance
2018-03-01
2017 Trust Services Criteria became effective — replaced the 2014 TSC.
2022-06-15
AICPA published updated points of focus for the 2017 TSC — same criteria, refreshed implementation guidance.
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs