Blog Post
7 min read

What controls are required for SOC 2® reports?

Mike DeKock, CPA, Founder & CEO

April 27, 2023
The Compass:
Helping you navigate the myths, intricacies, and questions around SOC 2 compliance.

Q:  What controls are required for SOC 2®?

A:  MJD Answer

There is nuance to this question, and other well-meaning and very smart people that I respect might give a different answer. But within the volumes of literature that set the standards, the true answer is this: There are absolutely no control requirements for SOC 2 reports.  

SOC 2 is actually not a control framework at all. It is a reporting and control evaluation framework. The Description Criteria provide benchmarks for how to write the report, and the Trust Services Criteria are used to evaluate the controls. Both require significant judgment and considerable skill to use, but they’re just tools to describe (and audit) how the company meets its business objectives.

Does that mean you can just do whatever you want? Of course not. 

The report needs to be accurate, and it needs to meet the expectations of the most important people that will read it: your customers. They will expect a level of maturity with written policies and procedures around how you manage access, train your people, monitor for system vulnerabilities, and all the other best practices, which ultimately gets most companies to a similar level, which is why it’s ok to forgive people that incorrectly say “the requirements of SOC 2.” However, taking that hard-lined, requirement-based approach creates waste, slows down progress, and damages culture in ways that introduce real security risks, which is why starting with a true understanding of the rule book is critical before you start playing the game. 

ChatGPT Answer

SOC 2 (System and Organization Controls 2) is a type of audit report that provides assurance on the controls of a service organization's system. The requirements for SOC 2 compliance are based on the Trust Services Criteria (TSC) developed by the American Institute of Certified Public Accountants (AICPA).

The actual requirements for SOC 2 compliance vary depending on the specific trust service criteria being audited. The five trust service criteria are:

  1. Security: The system is protected against unauthorized access (both physical and logical).
  2. Availability: The system is available for operation and use as committed or agreed.
  3. Processing integrity: System processing is complete, accurate, timely, and authorized.
  4. Confidentiality: Information designated as confidential is protected as committed or agreed.
  5. Privacy: Personal information is collected, used, retained, disclosed, and destroyed in accordance with the organization's privacy notice and the criteria set forth in Generally Accepted Privacy Principles (GAPP).

To achieve SOC 2 compliance, a service organization must have controls in place that address each of these criteria. The controls must be designed effectively and operating as intended. Additionally, the controls must be monitored and tested periodically to ensure they remain effective over time.

The actual requirements for SOC 2 compliance can be quite detailed and can vary depending on the size and complexity of the service organization. It is important to engage a qualified auditor to help guide the organization through the SOC 2 audit process and to ensure that all of the necessary requirements are met.

More posts

Blog Post
How do I choose a SOC auditor?

Interviewing auditors is a necessary step in the process as you begin your SOC exam. Here we outline some questions and considerations to help you along the way.

ChatGPT and Security

Jemurai shares their ideas and research to present a balanced view on the security implications of using ChatGPT

Unlocking Trust: How SOC 2 Validated Our Security Program

Check out Software Secured's story focused on the process of working on their SOC 2 report with MJD Advisors