Skip to content
ContractualAICPAUSv2017 (rev. 2022)

SOC 2

SOC 2 (AICPA Trust Services Criteria)

An attestation framework for service organizations based on five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. The Common Criteria (CC series) form the mandatory security baseline.

Official source ↗

Who it applies to

SaaS & cloudService organizationsUS-centric

Service organizations — especially SaaS and cloud providers — that store or process customer data and are asked to demonstrate security through an independent auditor's report. Driven by customer and procurement requirements rather than law.