SOC 2 examination
163472·updated Aug 30, 2026An examination engagement to report on whether ( a ) the description of the service organization's system is in accordance with the description criteria, ( b ) the controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria, and ( c ) in a type 2 report, the controls operated effectively to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria. The SOC 2 examination is performed in accordance with the attestation standards and AICPA Guide SOC 2 ® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy .
Source
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.
Classifications
Entity Type
Sensitivity
Information Class
Variants
Framework definitions
- §1 · glossary
- An examination engagement to report on whether ( a ) the description of the service organization's system is in accordance with the description criteria, ( b ) the controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria, and ( c ) in a type 2 report, the controls operated effectively to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria. The SOC 2 examination is performed in accordance with the attestation standards and AICPA Guide SOC 2 ® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy .Attribution from the CKI glossary mapping stage (glossary)
- §1 · legacy_primary
- An examination engagement to report on whether ( a ) the description of the service organization's system is in accordance with the description criteria, ( b ) the controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria, and ( c ) in a type 2 report, the controls operated effectively to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria. The SOC 2 examination is performed in accordance with the attestation standards and AICPA Guide SOC 2 ® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy .DR-088 backfill from the noun definition column