Reference · LeakTrace Intelligence Team
SOC 2.
SOC 2 — Trust Services Criteria (AICPA)
At a glance
- Jurisdiction
- US Federal
- Breach reporting deadline
- Contractual — controlled by customer BAAs and MSAs
- Applies to
- AllSaasService Organizations
- Authoritative source
- https://www.aicpa-cima.com/topic/audit-assurance/audit-and-a…
- Last updated
- August 5, 2026
## What it is
SOC 2 (Service Organization Control 2) is a reporting framework developed by the American Institute of Certified Public Accountants (AICPA). It is not a certification, not a law, and not enforced by any government agency — it is an independent auditor's report on a service organization's controls relevant to the Trust Services Criteria (TSC). It has become a de facto market requirement for enterprise B2B SaaS and cloud service providers.
## Who it applies to
Any service organization whose services could impact user entities' financial reporting, security, or trust. Common adopters include SaaS platforms, cloud infrastructure providers, managed service providers, data processors, and any organization whose customers require independent third-party attestation of control effectiveness.
## Trust Services Criteria
- **Security (Common Criteria — required):** Protection against unauthorized access (physical and logical), unauthorized disclosure, and damage to systems
- **Availability:** System is available for operation and use as committed
- **Processing Integrity:** System processing is complete, valid, accurate, timely, and authorized
- **Confidentiality:** Information designated as confidential is protected as committed
- **Privacy:** Personal information is collected, used, retained, disclosed, and disposed of in accordance with the entity's privacy notice
The Security TSC is mandatory in every SOC 2 examination. The other four are optional and selected based on the service organization's commitments to user entities.
## Type 1 vs Type 2 reports
- **Type 1:** Auditor's opinion on the design of controls as of a specific date. Point-in-time snapshot.
- **Type 2:** Auditor's opinion on the design AND operating effectiveness of controls over a period of time (typically 6-12 months). Standard for mature vendor due diligence.
Type 2 reports are what enterprise procurement teams typically require; Type 1 is often the initial step for organizations pursuing their first SOC 2.
## The Common Criteria (CC series)
Under the 2017 Trust Services Criteria (revised 2022 points of focus), Security is organized into nine Common Criteria series:
- **CC1 — Control Environment:** Integrity, ethics, governance, competence
- **CC2 — Communication and Information:** Internal and external communication
- **CC3 — Risk Assessment:** Identification and analysis of risks
- **CC4 — Monitoring Activities:** Ongoing and separate evaluations
- **CC5 — Control Activities:** Design and deployment of control activities
- **CC6 — Logical and Physical Access Controls:** Restrict access appropriately
- **CC7 — System Operations:** Detect and respond to threats
- **CC8 — Change Management:** Authorize, design, develop, implement changes
- **CC9 — Risk Mitigation:** Identify, select, and develop risk mitigation activities
## Breach handling within SOC 2
SOC 2 has no statutory breach-notification deadline — obligations are contractual, flowing through the Master Services Agreement (MSA), Data Processing Addendum (DPA), and any applicable Business Associate Agreement. However, CC7 controls typically require:
- Documented incident response plan
- Timely detection and response to security incidents
- Notification of user entities per contractual commitments
- Post-incident analysis and corrective action
## Auditor selection and scope
SOC 2 examinations must be performed by a licensed CPA firm. The auditor selects a sample of controls to test based on materiality and risk. Report scoping — what systems, services, and time periods are covered — is negotiated between the service organization and auditor and disclosed on the report cover page.
## How LeakTrace aligns
LeakTrace supports service organizations with continuous external-surface monitoring that directly maps to CC6 (logical access), CC7 (system operations / threat detection), and CC9 (risk mitigation) evidence. Documentation is prepared to slot into SOC 2 auditor evidence requests with dates, chain-of-custody, and control-linkage annotations.
Key provisions
- Trust Services Criteria — Security (CC series)
- Common Criteria applied in every SOC 2 examination; covers governance, risk assessment, monitoring, control activities, access controls, operations, change management, and risk mitigation.
- CC6.1 — Logical and physical access
- Restrict logical and physical access to protect information assets from security events.
- CC6.6 — External access controls
- Implement logical access security measures to protect against threats from sources outside the system boundaries.
- CC7.2 — Anomaly detection
- Monitor system components and the operation of controls for anomalies indicative of malicious acts, natural disasters, or errors.
- CC7.4 — Incident response
- Respond to identified security incidents by executing a defined incident response program.
- Vendor management (CC9.2)
- Assess and manage risks associated with vendors and business partners with access to information assets.
Recent amendments & guidance
2018-03-01
2017 Trust Services Criteria became effective — replaced the 2014 TSC.
2022-06-15
AICPA published updated points of focus for the 2017 TSC — same criteria, refreshed implementation guidance.
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs