Audit & Assurance
SOC 2
AICPA attestation report on a service organisation's Trust Services Criteria controls.
SOC 2 reports come in Type I (design at a point in time) and Type II (operating effectiveness over a period, typically 6–12 months). The Security criterion is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional add-ons.