O Oluma Cyber Security Framework Files · No. 04 Attestation · Service Organizations SOC 2 Trust Services Criteria The report enterprise buyers ask for before they trust you with their data — an independent auditor’s word that your controls aren’t just designed well, they actually work. 2017/’22 TSP §1005 CriteriaCC1–9 CommonI & II Types SOC CC1-95 TSCI/II How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem Death by security questionnaire As companies moved their data into other people’s clouds, every enterprise customer wanted the same thing: proof that the vendor could be trusted. So they sent questionnaires — hundreds of questions, each buyer slightly different — and vendors spent weeks answering the same things over and over. Worse, a vendor grading its own homework isn’t proof of anything. What was missing was an independent, standardized way to say “our security controls actually work” — once — in a form every customer would accept. 02 Why It Was Created One report, many customers The AICPA — the body that governs U.S. accountants — built SOC so an independent CPA firm could examine a service organization’s controls and issue a report that answers every customer at once. It’s made for companies that hold other people’s data: SaaS, cloud, payroll, data centers. The core ideaHave a neutral third party test your controls against a common yardstick, then publish their opinion. Buyers stop interrogating you one by one — they just read the report. That yardstick is the Trust Services Criteria, and the auditor’s signed opinion is what gives it weight. 03 The Story Behind It From an audit standard to the SaaS handshake 1992SAS 70An auditing standard for financial-reporting controls — quickly (and awkwardly) repurposed by tech vendors trying to prove security. 2011SOC is bornThe AICPA replaced the misused SAS 70 with a purpose-built family: SOC 1 for financial controls, SOC 2 and SOC 3 for security and operations. 2017The five criteriaThe Trust Services Criteria were restructured into five categories and aligned to the COSO internal-control framework — the shape SOC 2 still uses. 2022Points of focus refreshedThe current release updated the implementation guidance (the “points of focus”) without changing the five criteria — stable since 2017. 04 How It Works Five criteria, two report types An auditor tests your controls against the Trust Services Criteria — five categories. Only Security is mandatory (its “Common Criteria,” CC1–CC9, form the backbone of every report). You add the others based on what you actually promise customers. Security ★ requiredAvailabilityProcessing IntegrityConfidentialityPrivacy Then there are two flavors of report, and the difference matters enormously to buyers: Type IDesigned well — on one dayThe auditor confirms your controls are suitably designed at a single point in time. A snapshot. Type IIActually working — over timeThe auditor tests that controls operated effectively across a period, usually 6–12 months. This is the one enterprises want. It’s an attestation, not a certificateThere is no “SOC 2 certificate.” You get an auditor’s report and opinion, and it isn’t simple pass/fail — the report openly describes any exceptions, and readers judge for themselves. 05 Real-World Example A B2B SaaS clears its sales blockers A B2B SaaS keeps losing deals in procurement — not on price, but on “send us your SOC 2.” So they scope one to what their buyers care about and commit to a Type II over six months. Their SOC 2 playScope to the promise, then prove it over time Include Security (required) plus Availability Map controls to the Common Criteria, CC1–CC9 Run the controls for a six-month observation window Let an independent CPA firm test and opine Share the report with prospects under NDA One report now answers the security section of every enterprise deal — and the sales cycle gets measurably shorter. 06 Who Uses It The default trust signal in U.S. B2B ☁️SaaS & cloudThe near-universal ask for software and infrastructure vendors selling to U.S. enterprises. 🛠️MSPs & fintechManaged providers, payment platforms, and data processors that operate systems on customers’ behalf. 🔎Vendor-risk teamsOn the buyer side, procurement and third-party risk functions consume SOC 2 reports to clear vendors. It doesn’t stand alone — the criteria cross-reference other frameworks, so the same evidence stretches further. aligns with ISO 27001NIST CSFCOSOHIPAANIST 800-53 07 Career Relevance Where GRC meets the sales pipeline SOC 2 is one of the busiest corners of GRC, because it ties directly to revenue — no report, no enterprise deal. It also sits on both sides of the table: teams that earn reports and vendor-risk teams that read them (exactly the world of tools like BitSight, SecurityScorecard, and OneTrust). Readiness leadGet audit-readyScope criteria, map controls to CC1–CC9, and close gaps before the auditor arrives. Evidence & opsSustain the controlsCollect the continuous evidence a Type II demands across a 6–12 month window. Vendor-risk analystRead the other sideInterpret suppliers’ SOC 2 reports — scope, exceptions, and carve-outs — to judge whether a vendor is safe to onboard. Understanding what a SOC 2 report really says — and doesn’t — is a daily GRC skill. 08 Strengths & Challenges Honest trade-offs ✦ Strengths Independent, buyer-trusted assurance Flexible scope — include only the criteria you promise Replaces endless customer questionnaires Cross-references ISO 27001, CSF, and COSO Type II proves controls work over real time ⚠ Challenges Recurring audit cost, year after year Covers only a window — not a permanent guarantee Largely a U.S. convention; less known abroad Report quality and scope vary — you must read carefully An attestation, not a certificate 09 Final Takeaway ISO proves it to the world. SOC 2 proves it to your customers — with an auditor’s name on the line.It turns “trust us” into an independent, testable report that unblocks enterprise deals and ends the questionnaire treadmill. Learn to both earn one and read one, and you’re fluent in the language vendor-risk runs on.