Attestation · Last verified
SOC 2
SOC 2 is an AICPA attestation: the output is an examination report, not a certificate, examining a service organization's system and controls. The AICPA describes the engagement itself: "SOC 2 engagements: Assertion-based examination of a service organization's description of its system and its controls relevant to security, availability, processing integrity, confidentiality, or privacy.".
- Class
- Attestation
- Owner
- AICPA
- Last verified
What it is
SOC 2 belongs to the AICPA's SOC reporting suite. The AICPA's own pages describe the output as a report — the term "certification" does not appear.
The AICPA describes the wider suite in its own words: "System and Organization Controls (SOC) is a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations."
The AICPA describes the SOC 2 engagement itself: "SOC 2 engagements: Assertion-based examination of a service organization's description of its system and its controls relevant to security, availability, processing integrity, confidentiality, or privacy."
Who owns it
SOC 2 is owned and maintained by the AICPA, whose Trust Services Criteria define the examination's subject matter.
Who assesses it
The AICPA describes the assessor side in its own words: "CPAs can use the AICPA's various SOC offerings to provide assurance reports." Whether a SOC 2 examination may only be performed by a licensed CPA firm was not verified in the sources reviewed as of 28 August 2026.
Sources
- AICPA — SOC 2 (scheme owner) ↗ — accessed
- AICPA — Trust Services Criteria (2017, revised points of focus 2022) ↗ — accessed
- AICPA — illustrative SOC 2 Type 2 report (SSAE 21) ↗ — accessed
- AICPA — System and Organization Controls: SOC Suite of Services ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.