# What is SOC 2?

> SOC 2 is an audit report, defined by the AICPA, on how a service organisation implements controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report assesses control design at a point in time; a Type II report tests operating effectiveness across a period, commonly three to twelve months.

Last updated: 2026-07-27

SOC 2 is frequently described as a certification. It is not. There is no pass mark and no certificate — it is an auditor's opinion on a set of controls the organisation itself defined, within a scope the organisation itself set. Two SOC 2 reports are therefore not automatically comparable.

That makes three things worth checking rather than accepting the badge. First, the scope: which systems and which of the five criteria were actually included. A report covering only Security is common and legitimate, but it says nothing about availability or privacy. Second, Type I versus Type II: a Type I says the controls looked right on one day. Third, the exceptions section, where the auditor records controls that did not operate as described. A clean-looking report with material exceptions is a different object from one without.

For buyers in Japan, SOC 2 often appears alongside rather than instead of ISO/IEC 27001. They answer different questions: ISO 27001 certifies that a management system meeting the standard exists; SOC 2 reports on whether specific controls operated. Enterprises with US and Japanese operations frequently ask for both.

For vendors, the report is expensive to obtain and then gets re-summarised by hand into every buyer's questionnaire — which is why the same evidence is transcribed dozens of times a year.

Sources: [1] https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2

## Related terms

- [Security questionnaire](https://agent-door.com/glossary/security-questionnaire)
- [ISO/IEC 27001 (ISMS)](https://agent-door.com/glossary/iso-27001)
- [Vendor evaluation](https://agent-door.com/glossary/vendor-evaluation)

## Frequently asked questions

### Is SOC 2 Type II always better than Type I?

Type II carries more evidence because controls were tested over a period rather than on a single date. A first-time Type I is normal for a young company and is not a red flag on its own — but a company that stays on Type I for years is worth asking about.

### Does SOC 2 satisfy Japanese enterprise procurement?

It helps but is rarely sufficient on its own. Many Japanese buyers are more familiar with ISMS/ISO 27001 and will still issue their own チェックシート. Requirements vary by company, so confirm what a specific buyer accepts rather than assuming.

---
Canonical HTML: https://agent-door.com/glossary/soc-2
