SOC 2 Report
SOC 2 Report is an independent attestation report under the AICPA Trust Services Criteria; a Type I assesses control design at a point in time, while a Type II tests operating effectiveness over a period.
Why it matters
A SOC 2 report is among the most requested pieces of evidence in security reviews and can answer many questionnaire items at once.
Where it appears in the workflow
Shared as primary evidence during security reviews and often gated behind an NDA in a trust center.
Common mistakes
- Treating soc 2 report as a universal term with no workflow context.