Service Organisation Control (SOC 2) is a framework that is used to help organisations maintain information security and assure clients of their ability to protect sensitive data, particularly those operating or looking to operate in the US market.  It is published by the American Institute of Certified Public Accountants (AICPA), and involves a CPA auditing against a selection of up to 5 trust services criteria (TSC) and subsequently producing a report on your information security processes and controls.   This report is not intended to be public facing, and can only be shared with specific interested parties, such clients, prospective clients, and auditors, in order to demonstrate to these parties that your organisation handles information securely.  

It is important to note that SOC 2 is an attestation, not a certification, and there is no concept of a SOC 2 ‘pass’ or ‘fail’.  The output of a SOC 2 audit is the report described above, which you will receive regardless of your organisation’s level of compliance with the framework’s requirements.  The CPA firm performing the audit will, however, provide an opinion on your alignment with the selected TSC.  If the auditor does not identify any significant issues, you will receive an ‘unqualified’ report.  However, if there are significant issues and findings raised during the audit, you may receive a ‘qualified’ report.

The whole gap analysis process was very informative for all departments of the business. Our URM consultant was great at explaining the SOC2 audit process and what evidence may be required for each area. As a business, it has really assisted us in our implementation strategy and improving our compliance programme as a whole.
Cyber security services provider
Contact SOC 2 Experts TodayLearn more about SOC 2

Preparing for a Successful SOC 2 Audit

Published on
17 Oct
2025

URM’s blog offers key advice on what to expect from your SOC 2 audit in practice, the types of evidence you will need to provide, how best to prepare, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
29/8/2025
SOC 2 Explained

URM’s blog answers key questions about SOC 2, including what it is & who it applies to, why it is beneficial, how SOC 2 reports are structured & more.

Read more
"
We would like to pass on our gratitude to our consultant for all his hard work and advice during our 3-year re-certification and assessment against the new Standard. After seven days of auditing, we have two OFIs that the assessors have put forward from the audits. This pays testament to our URM consultant, his hard work, eye for detail and advice given, both during the audits and during all the works beforehand.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.