Skip to main content
Back to Glossary
management

SOC 2 Type II

SOC 2

A US auditing standard for service organisations covering security, availability, processing integrity, confidentiality and privacy controls over a defined period.

Full Definition

<p>SOC 2 (System and Organisation Controls 2) is an auditing framework developed by the American Institute of CPAs (AICPA) for service organisations — including data centre operators and cloud providers. It assesses controls relevant to five Trust Service Criteria: security, availability, processing integrity, confidentiality and privacy.</p><p>A SOC 2 Type II report covers a defined audit period (typically 6–12 months) and tests whether specified controls were operating effectively throughout that period — not just at a point in time (Type I). SOC 2 Type II is increasingly required by enterprise customers as a prerequisite for vendor selection. For colocation operators, the security (Common Criteria) and availability criteria are most relevant, covering physical access controls, environmental monitoring, incident response and business continuity.</p>

Also Known As

SOC 2 Type 2AICPA SOC 2Trust Service Criteria

Source Reference

AICPA SOC 2 Reporting on Controls at a Service Organization

Related Terms