Glossary

What is SOC 2?

SOC 2 is an audit report, defined by the AICPA, on how a service organisation implements controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report assesses control design at a point in time; a Type II report tests operating effectiveness across a period, commonly three to twelve months.

Last updated:

SOC 2 is frequently described as a certification. It is not. There is no pass mark and no certificate — it is an auditor's opinion on a set of controls the organisation itself defined, within a scope the organisation itself set. Two SOC 2 reports are therefore not automatically comparable.

That makes three things worth checking rather than accepting the badge. First, the scope: which systems and which of the five criteria were actually included. A report covering only Security is common and legitimate, but it says nothing about availability or privacy. Second, Type I versus Type II: a Type I says the controls looked right on one day. Third, the exceptions section, where the auditor records controls that did not operate as described. A clean-looking report with material exceptions is a different object from one without.

For buyers in Japan, SOC 2 often appears alongside rather than instead of ISO/IEC 27001. They answer different questions: ISO 27001 certifies that a management system meeting the standard exists; SOC 2 reports on whether specific controls operated. Enterprises with US and Japanese operations frequently ask for both.

For vendors, the report is expensive to obtain and then gets re-summarised by hand into every buyer's questionnaire — which is why the same evidence is transcribed dozens of times a year.

Sources: [1]

Frequently asked questions

Is SOC 2 Type II always better than Type I?
Type II carries more evidence because controls were tested over a period rather than on a single date. A first-time Type I is normal for a young company and is not a red flag on its own — but a company that stays on Type I for years is worth asking about.
Does SOC 2 satisfy Japanese enterprise procurement?
It helps but is rarely sufficient on its own. Many Japanese buyers are more familiar with ISMS/ISO 27001 and will still issue their own チェックシート. Requirements vary by company, so confirm what a specific buyer accepts rather than assuming.

Skip the discovery calls.

Describe what you need and let AgentDoor's agents interview the vendors for you — you get a decision-ready shortlist, not six meetings.

We'll reach out at launch. No spam, ever.