Documentation / Platform glossary / SOC 2

SOC 2

In Short

SOC 2 is an auditing standard for service organizations, developed by the AICPA, that examines whether a company's controls over security, availability, processing integrity, confidentiality, and privacy work as described. An independent auditor issues the report; the vendor does not certify itself.

SOC 2 concept diagram

Definition

SOC 2 reports are built on the AICPA's Trust Services Criteria. Security is always in scope; availability, processing integrity, confidentiality, and privacy are included at the organization's discretion, which is why two SOC 2 reports can cover very different ground.

The distinction that matters most in practice is between report types. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report tests whether those controls actually operated effectively across a review period — typically three to twelve months — and includes the auditor's test results and any exceptions found. Type II is substantially more meaningful, because design without evidence of operation proves very little.

SOC 2 is an attestation, not a certification. There is no pass mark and no certificate; there is an auditor's opinion, a description of the system, and a list of exceptions. Reading the exceptions is usually more informative than confirming the report exists.

Why It Matters

SOC 2 lets an organization evaluate a vendor's control environment without auditing it directly, which is the only workable approach at scale. It is usually requested under NDA, so the report itself is not public.

The common failure is treating the report as a checkbox. A Type II covering only Security tells you nothing about availability commitments, and a report whose scope excludes the product you are buying tells you nothing at all. Scope, period, and exceptions are the substance.

How QueryTek Uses It

QueryTek documents SOC 2 as evaluation vocabulary so teams can frame diligence questions precisely — which report type, which criteria, which period. Current QueryTek attestation status is communicated through the approved claims register and direct engagement rather than asserted in public documentation.

Related Terms