← ALL FRAMEWORKS

SOC 2

Audit Attestation

Issued by AICPA

SOC 2 is an audit report defined by the AICPA and built on the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is mandatory in every SOC 2 report (the Common Criteria, CC1–CC9); the other four are added based on what a service organization actually commits to its customers. It's typically pursued by SaaS companies, cloud providers, and other service organizations that store or process customer data, usually because enterprise customers require it during vendor due diligence. There's no single numbered "current version" — the AICPA periodically revises its guidance, and audits are conducted against whatever's current for that audit period.

Get notified the moment SOC 2 actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

clarification

The fetched content is a general AICPA/CIMA news feed covering sustainability reporting studies, tax advisory news, leadership appointments, and surveys — none of which address changes to the SOC 2 framework itself.

VIEW SOURCE ↗
SOC 2 Updates & Compliance Changes | ComplianceScope