SOC 2 Type II

SOC 2 Type II is an independent audit report on whether a service provider's security controls were designed appropriately and operated effectively across a period of time, typically six to twelve months. Banks require it from vendors that touch customer data.

Formula

What the report is

SOC 2 is an examination performed by an independent CPA firm against the AICPA's Trust Services Criteria. The auditor forms an opinion on a service organization's controls over security and, where in scope, availability, processing integrity, confidentiality and privacy.

The output is a report, not a certificate or a badge issued by a governing body. It contains the auditor's opinion, management's description of the system, the control objectives, the tests performed, and, importantly, any exceptions the auditor found.

Type I versus Type II

A Type I report evaluates whether controls are designed appropriately as of a single date. It is a snapshot. A vendor can pass a Type I by having the right policies written down on the day the auditor looks.

A Type II report evaluates whether those controls operated effectively over an observation window, usually six to twelve months. The auditor samples evidence across that period: access reviews actually performed, changes actually approved, backups actually tested, incidents actually handled. This is why a bank's vendor risk review treats Type II as the real answer and Type I as a starting position.

The five trust services criteria

  • Security. Required in every SOC 2. Protection against unauthorized access, both logical and physical.
  • Availability. Whether the system is available for operation as committed.
  • Processing integrity. Whether processing is complete, valid, accurate and timely.
  • Confidentiality. Whether information designated confidential is protected as committed.
  • Privacy. Whether personal information is collected, used, retained and disposed of in line with the organization's own notice.

Only Security is mandatory. A report scoped to Security alone is a valid SOC 2 Type II, so which criteria were in scope is one of the first things a reviewer should check rather than assume.

What a bank's vendor risk team looks for

The cover page is the least useful part of the report. Reviewers who know what they are doing go to four places.

The opinion. Unqualified is clean. A qualified opinion means the auditor found something material, and the reason matters more than the label.

The observation period. A report covering a window that ended fourteen months ago tells you about a system that may no longer exist. Most institutions want a report no older than twelve months, plus a bridge letter covering the gap since the period ended.

The exceptions. Every real Type II report has some. What a reviewer is judging is severity, whether they cluster around a weak control area, and what management said it did about them.

Subservice organizations and complementary user entity controls. The report will name infrastructure providers carved out of scope, and it will list controls the vendor assumes you operate on your side. Those assumptions are frequently where the actual gap sits.

What it does not tell you

SOC 2 Type II is an assurance report on control operation, not a guarantee of outcomes and not a penetration test. It says the controls the organization described were in place and worked during the observation window. It does not say the architecture is well designed, that the vendor will remain solvent, or that data will never be exposed. It is one input into a vendor risk decision, and the strongest single one available, but it does not replace the rest of the diligence.

Related terms

Examiner-ready documentation, policy exception.