Attestation, assessment and label schemes
SOC 2:TSC 2017 (rev. 2022)
An attestation engagement, not a certification. A CPA firm renders an opinion on whether controls were suitably designed (Type I) and operated effectively over a period (Type II). The deliverable is a report a customer reads, not a wall certificate.
What you receive
Attestation report and opinion letter
Issued only by a licensed CPA firm under AICPA attestation standards. There is no such thing as a SOC 2 certificate.
This scheme does not produce a certificate. If a body has offered you one for SOC 2, that alone tells you what their audit work is worth.
Who needs it
Almost every B2B SaaS company selling into the United States. Frequently requested alongside, not instead of, ISO/IEC 27001.
Prerequisites
A defined observation period for Type II. Controls must have been operating throughout it.
How this engagement is delivered
Programme managed by Securo Cert LLC. Audit and certification decision by the appointed partner body.
Securo Cert document not accreditedThe partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.
Frequent questions
What do we actually receive?
Attestation report and opinion letter. Issued only by a licensed CPA firm under AICPA attestation standards. There is no such thing as a SOC 2 certificate.
How long is it valid?
Type I is a point in time. Type II covers an observation period, normally three to twelve months, repeated annually.
What has to be in place first?
A defined observation period for Type II. Controls must have been operating throughout it.