Skip to content
Oluma Cyber Security Awareness
Attestation · Service Organizations

SOC 2 Trust Services Criteria

The report enterprise buyers ask for before they trust you with their data — an independent auditor’s word that your controls aren’t just designed well, they actually work.

2017/’22 TSP §1005 CriteriaCC1–9 CommonI & II Types
01 The Problem

Death by security questionnaire

As companies moved their data into other people’s clouds, every enterprise customer wanted the same thing: proof that the vendor could be trusted. So they sent questionnaires — hundreds of questions, each buyer slightly different — and vendors spent weeks answering the same things over and over.

Worse, a vendor grading its own homework isn’t proof of anything. What was missing was an independent, standardized way to say “our security controls actually work” — once — in a form every customer would accept.

03 The Story Behind It

From an audit standard to the SaaS handshake

1992
SAS 70
An auditing standard for financial-reporting controls — quickly (and awkwardly) repurposed by tech vendors trying to prove security.
2011
SOC is born
The AICPA replaced the misused SAS 70 with a purpose-built family: SOC 1 for financial controls, SOC 2 and SOC 3 for security and operations.
2017
The five criteria
The Trust Services Criteria were restructured into five categories and aligned to the COSO internal-control framework — the shape SOC 2 still uses.
2022
Points of focus refreshed
The current release updated the implementation guidance (the “points of focus”) without changing the five criteria — stable since 2017.
04 How It Works

Five criteria, two report types

An auditor tests your controls against the Trust Services Criteria — five categories. Only Security is mandatory (its “Common Criteria,” CC1–CC9, form the backbone of every report). You add the others based on what you actually promise customers.

Security ★ requiredAvailabilityProcessing IntegrityConfidentialityPrivacy

Then there are two flavors of report, and the difference matters enormously to buyers:

Type I
Designed well — on one day
The auditor confirms your controls are suitably designed at a single point in time. A snapshot.
Type II
Actually working — over time
The auditor tests that controls operated effectively across a period, usually 6–12 months. This is the one enterprises want.
It’s an attestation, not a certificate

There is no “SOC 2 certificate.” You get an auditor’s report and opinion, and it isn’t simple pass/fail — the report openly describes any exceptions, and readers judge for themselves.

06 Who Uses It

The default trust signal in U.S. B2B

☁️
SaaS & cloud
The near-universal ask for software and infrastructure vendors selling to U.S. enterprises.
🛠️
MSPs & fintech
Managed providers, payment platforms, and data processors that operate systems on customers’ behalf.
🔎
Vendor-risk teams
On the buyer side, procurement and third-party risk functions consume SOC 2 reports to clear vendors.

It doesn’t stand alone — the criteria cross-reference other frameworks, so the same evidence stretches further.

aligns with ISO 27001NIST CSFCOSOHIPAANIST 800-53
07 Career Relevance

Where GRC meets the sales pipeline

SOC 2 is one of the busiest corners of GRC, because it ties directly to revenue — no report, no enterprise deal. It also sits on both sides of the table: teams that earn reports and vendor-risk teams that read them (exactly the world of tools like BitSight, SecurityScorecard, and OneTrust).

Readiness lead
Get audit-ready
Scope criteria, map controls to CC1–CC9, and close gaps before the auditor arrives.
Evidence & ops
Sustain the controls
Collect the continuous evidence a Type II demands across a 6–12 month window.
Vendor-risk analyst
Read the other side
Interpret suppliers’ SOC 2 reports — scope, exceptions, and carve-outs — to judge whether a vendor is safe to onboard.

Understanding what a SOC 2 report really says — and doesn’t — is a daily GRC skill.

09 Final Takeaway

ISO proves it to the world. SOC 2 proves it to your customers — with an auditor’s name on the line.

It turns “trust us” into an independent, testable report that unblocks enterprise deals and ends the questionnaire treadmill. Learn to both earn one and read one, and you’re fluent in the language vendor-risk runs on.