# SOC 2 Overview | Secureframe

canonical: https://secureframe.com/hub/soc-2/overview

Safeguarding customer and business data is a growing priority for companies across industries and growth stages, and a SOC 2 audit is becoming an essential piece of the security puzzle. 

If you’re wondering what SOC 2 is and why it’s so important, you’re in the right place. 

This is the ultimate SOC 2 overview made for beginners. 

We’ve broken down the SOC 2 framework into a series of clear-cut, jargon-free primers on the fundamentals of SOC 2 compliance. 

You’ll learn the differences between SOC standards, the essentials of the AICPA Trust Services Criteria, how to implement SOC 2 controls — everything you need to understand the requirements of SOC 2 and decide if pursuing compliance is the right choice for your business.

## Beginner: I'm New to SOC 2

**Let’s start from the beginning. **

Understanding the underlying principles of SOC 2 compliance helps expedite the process from when you first start preparing and scoping your audit to when you receive your report in hand.

Here’s what you need to know.

![](https://prismic-io.s3.amazonaws.com/secureframe-com/a1ff73a6-1ebf-4a39-8f4a-faaa3445d568_1.+Hub+Content_+SOC+2+Beginner+01%402x.png)

## SOC 2 Basics

Data breaches are becoming increasingly common. The number of publicly reported US data breaches [rose by 38%](https://www.idtheftcenter.org/data-breaches-are-up-38-percent-in-q2-2021-the-identity-theft-resource-center-predicts-a-new-all-time-high-by-years-end/) in Q2 of 2021 compared to Q1. 

With a threat landscape that’s constantly evolving, companies have a lot of justified concerns around safeguarding sensitive and proprietary information. 

So what can your organization do to protect itself from a breach?

Various standards and certifications exist to help organizations strengthen their overall security posture and prove their trustworthiness to customers, including [ISO 27001](https://secureframe.com/products/iso-27001), GDPR, CCPA, [HIPAA](https://secureframe.com/products/hipaa), [PCI DSS](https://secureframe.com/products/pci), and many others. 

One of the most highly regarded of these security frameworks is the System and Organization Controls 2 standard, or SOC 2. 

## Who Created SOC 2 and Why? 

SOC 2 was created by the American Institute of Certified Public Accountants (AICPA) in 2010. It includes a set of requirements to help organizations safeguard customer data that’s stored in the cloud. 

These requirements are based on five Trust Services Criteria (TSC), defined by the AICPA as: 

- **Security**: Protecting information from unauthorized access
- **Availability**: Ensuring employees and clients can rely on your systems to perform their work
- **Processing Integrity**: Verifying that company systems operate as intended
- **Confidentiality**: Protecting confidential information by limiting its access, storage, and use
- **Privacy**: Safeguarding sensitive personal information against unauthorized users 

![SOC 2 Trust Service Criteria](https://images.prismic.io/secureframe-com/bea665b3-3e77-4036-a6a7-c03bfb36a85a_Hub+Content_+What+is+SOC+2_+01%402x.png?auto=compress,format)

Ultimately, the purpose of SOC 2 is to help service organizations build trust with their customers. If your organization stores, processes, or transmits any kind of customer data, it’s likely that you’ll need to be SOC 2 compliant to compete in your market.

## How Do You Become SOC 2 Compliant? 

To become SOC 2 compliant, organizations must undergo a formal audit with a licensed CPA. During the audit, the auditor will evaluate a company’s security posture related to one or all of the Trust Service Criteria. 

Unlike more rigid security frameworks like ISO 27001, SOC 2 does not have a formal checklist of requirements or controls that every company must implement to achieve compliance. Instead, SOC 2 is more flexible, allowing each company to select which Trust Services Criteria apply to its services and putting in place security controls that satisfy TSC’s requirements.

Before beginning a formal SOC 2 audit, companies will define the scope of their audit. They determine which Trust Services Criteria apply (Security is always included). They also decide whether to pursue a Type I or Type II report and the timeframe for the audit (for Type II reports). 

## SOC 2 Type I vs. Type II Reports

In addition to defining which TSC apply, companies also need to decide whether to pursue a Type I or Type II SOC 2 report. 

A SOC 2 Type I report is a point-in-time report, which examines how a company’s internal controls are designed and implemented. 

A SOC 2 Type II report takes a longer view to examine how those controls perform over an extended period of time, typically 3-12 months.

![Type I Report and Type II Report](https://images.prismic.io/secureframe-com/1b9f404f-e227-419a-ba5b-fe8ae69f54e0_Hub+Content_+What+is+a+SOC+2++Report+02%402x.png?auto=compress,format)

Each type of report has its benefits and drawbacks. 

A Type I report is faster to complete and typically costs less, but it carries a little less weight with bigger customers. Plus, most customer requests for a SOC 2 report will specify Type II. Type I reports are most beneficial for companies who urgently need to prove SOC 2 compliance to capture sales. 

A Type II report takes longer to achieve and is more expensive, but it’s seen as the gold standard for data security. The longer the audit window for Type 2, the stronger the report. Most companies who don’t need a SOC 2 report immediately decide to pursue a Type II report. 

This section will explain the essentials of SOC 2 compliance in detail, including the Common Criteria and SOC 2 requirements.
