SOC 2 glossary for startups: 34 words explained
Short, plain definitions of the terms that come up in a first SOC 2. Each term has an anchor you can link to, and related Playbook lessons are linked where they go deeper.
A
Access review
A periodic check that each person's access to systems still matches their role, with removals recorded. Auditors often sample these in a Type II.
AICPA
The American Institute of Certified Public Accountants, which sets the standards and guidance CPA firms follow for SOC examinations.
AICPA peer review
The AICPA programme in which CPA firms that perform audit and attestation work have their quality reviewed by other practitioners. A useful question to ask any SOC 2 auditor.
Attestation
An engagement in which a CPA firm reports on a subject matter or an assertion made by another party. A SOC 2 report is an attestation report, not a certification.
Auditor independence
The requirement that the CPA firm examining your controls is free of relationships that could compromise its judgement, in fact or in appearance.
B
Bridge letter
A letter from your management covering the gap between the end of your last SOC 2 period and today. Also called a gap letter.
C
Carve-out method
A way of handling a subservice organization (such as your cloud provider) in which its controls are excluded from your report and covered by its own report.
Common criteria
The criteria under the Security category, which apply to every SOC 2 report.
Complementary user entity controls (CUECs)
Controls your customers must operate for your controls to work as described, listed in your report.
Compliance automation
Software that connects to your systems, tracks controls, collects evidence and manages policies for frameworks such as SOC 2.
Continuous monitoring
Automated checks that run on a schedule and flag controls that drift, such as a new account without multi-factor authentication.
Control
A policy, procedure or technical measure that addresses a risk, such as requiring code review before deployment.
CPA firm
A public accounting firm licensed to perform attest engagements. Only a CPA firm can issue a SOC 2 report.
Cross-mapping
Linking one control to the requirements of several frameworks so a single piece of evidence counts toward SOC 2, ISO 27001 and others.
E
Evidence
Records that prove a control exists and runs, such as exports, tickets, logs, screenshots and signed documents.
Exception
A test result in a Type II report where a control did not operate as described for a sampled item.
G
Gap assessment
A review of current controls against the chosen criteria to find what is missing before the audit. Also called a readiness assessment.
I
Integration
A connection between a compliance tool and one of your systems that checks settings or pulls evidence automatically.
ISO/IEC 27001
The international standard for information security management systems. The current edition, ISO/IEC 27001:2022, is Edition 3, published in October 2022.
M
Management assertion
A written statement by your management, included in the SOC 2 report, about the system description and controls.
O
Observation period
The period of time a Type II report covers, agreed between you and your auditor, during which controls must operate as described.
Opinion
The auditor's conclusion in the report. An unqualified opinion means no material issues were found; qualified, adverse and disclaimer opinions signal problems of increasing seriousness.
P
Penetration test
An authorised simulated attack on your application or infrastructure to find exploitable weaknesses. Not required by SOC 2 itself, but often requested by customers.
R
S
Scope
The product, systems, people, processes and data locations a SOC 2 report describes.
Security questionnaire
A list of security questions a customer sends a supplier during procurement. A SOC 2 report reduces, but rarely ends, questionnaires.
SOC 1
A report on controls relevant to a customer's financial reporting, used mainly by services that affect customers' financial statements.
SOC 3
A general-use summary report on the same criteria as SOC 2, meant for public sharing.
Subservice organization
A vendor whose services are part of your system, such as a cloud hosting provider, handled in your report by the carve-out or inclusive method.
T
Trust center
A public page that shows a company's security posture, certifications and documents, and lets buyers request reports such as SOC 2.
Trust Services Criteria
The AICPA criteria a SOC 2 report is measured against, in five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy.
Type I report
A SOC 2 report on the system description and the design of controls as of a specific date.
Type II report
A SOC 2 report that adds the operating effectiveness of controls over an observation period.