SOC 2 glossary for startups: 34 words explained

Short answer

Short, plain definitions of the terms that come up in a first SOC 2. Each term has an anchor you can link to, and related Playbook lessons are linked where they go deeper.

A

Access review

A periodic check that each person's access to systems still matches their role, with removals recorded. Auditors often sample these in a Type II.

Read more in the Playbook

AICPA

The American Institute of Certified Public Accountants, which sets the standards and guidance CPA firms follow for SOC examinations.

AICPA peer review

The AICPA programme in which CPA firms that perform audit and attestation work have their quality reviewed by other practitioners. A useful question to ask any SOC 2 auditor.

Read more in the Playbook

Attestation

An engagement in which a CPA firm reports on a subject matter or an assertion made by another party. A SOC 2 report is an attestation report, not a certification.

Audit period

Another name for the observation period of a Type II report.

See observation period

Auditor independence

The requirement that the CPA firm examining your controls is free of relationships that could compromise its judgement, in fact or in appearance.

B

Bridge letter

A letter from your management covering the gap between the end of your last SOC 2 period and today. Also called a gap letter.

Read more in the Playbook

C

Carve-out method

A way of handling a subservice organization (such as your cloud provider) in which its controls are excluded from your report and covered by its own report.

Common criteria

The criteria under the Security category, which apply to every SOC 2 report.

Complementary user entity controls (CUECs)

Controls your customers must operate for your controls to work as described, listed in your report.

Compliance automation

Software that connects to your systems, tracks controls, collects evidence and manages policies for frameworks such as SOC 2.

Continuous monitoring

Automated checks that run on a schedule and flag controls that drift, such as a new account without multi-factor authentication.

Control

A policy, procedure or technical measure that addresses a risk, such as requiring code review before deployment.

CPA firm

A public accounting firm licensed to perform attest engagements. Only a CPA firm can issue a SOC 2 report.

Cross-mapping

Linking one control to the requirements of several frameworks so a single piece of evidence counts toward SOC 2, ISO 27001 and others.

Read more in the Playbook

E

Evidence

Records that prove a control exists and runs, such as exports, tickets, logs, screenshots and signed documents.

Read more in the Playbook

Exception

A test result in a Type II report where a control did not operate as described for a sampled item.

G

Gap assessment

A review of current controls against the chosen criteria to find what is missing before the audit. Also called a readiness assessment.

I

Integration

A connection between a compliance tool and one of your systems that checks settings or pulls evidence automatically.

Read more in the Playbook

ISO/IEC 27001

The international standard for information security management systems. The current edition, ISO/IEC 27001:2022, is Edition 3, published in October 2022.

ISO/IEC 27001:2022 at iso.org

M

Management assertion

A written statement by your management, included in the SOC 2 report, about the system description and controls.

O

Observation period

The period of time a Type II report covers, agreed between you and your auditor, during which controls must operate as described.

Read more in the Playbook

Opinion

The auditor's conclusion in the report. An unqualified opinion means no material issues were found; qualified, adverse and disclaimer opinions signal problems of increasing seriousness.

P

Penetration test

An authorised simulated attack on your application or infrastructure to find exploitable weaknesses. Not required by SOC 2 itself, but often requested by customers.

R

Readiness assessment

See gap assessment: a pre-audit review to find and fix gaps.

See gap assessment

S

Scope

The product, systems, people, processes and data locations a SOC 2 report describes.

Security questionnaire

A list of security questions a customer sends a supplier during procurement. A SOC 2 report reduces, but rarely ends, questionnaires.

SOC 1

A report on controls relevant to a customer's financial reporting, used mainly by services that affect customers' financial statements.

SOC 3

A general-use summary report on the same criteria as SOC 2, meant for public sharing.

Subservice organization

A vendor whose services are part of your system, such as a cloud hosting provider, handled in your report by the carve-out or inclusive method.

T

Trust center

A public page that shows a company's security posture, certifications and documents, and lets buyers request reports such as SOC 2.

Read more in the Playbook

Trust Services Criteria

The AICPA criteria a SOC 2 report is measured against, in five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy.

Read more in the Playbook

Type I report

A SOC 2 report on the system description and the design of controls as of a specific date.

Read more in the Playbook

Type II report

A SOC 2 report that adds the operating effectiveness of controls over an observation period.

Read more in the Playbook

Where to next on the trail