SOC 2: What It Means for Your Organization
SOC 2 is the report a customer asks for when they want an independent look at how you protect their data. A licensed CPA firm examines your controls and writes the opinion. ALCON DTS helps you run the controls and keep the evidence ready. We do not issue the report.
Jump to an answer
At a glance
- SOC 2 is an attestation from a CPA firm, not a certificate.
- The criteria come from the American Institute of Certified Public Accountants. Security is always included. Availability, confidentiality, processing integrity, and privacy are added only if the report names them.
- Type I looks at design on one date. Type II looks at whether the controls operated over a period, often six to twelve months.
- A customer request is what starts this work. The standard does not apply to every firm.
- The report is shared under the terms the CPA firm and the customer set. It is not a public badge.
- ALCON DTS does not issue a SOC 2 report.
What is SOC 2?
SOC 2 stands for System and Organization Controls 2. It is a way for a service organization to describe its system and have a CPA firm examine the controls against the Trust Services Criteria.
The firm chooses the categories. Security is the common criteria and is always part of the examination. The other four are optional. A report that says Security only is a real SOC 2 report. A report that adds Availability or Confidentiality is a different scope, and the evidence has to match.
What it covers, and what it does not
It covers the system you describe: the services, the people, the software, the procedures, and the data the customer is asking about. The CPA firm tests the controls you claim for that system.
It does not replace a contract. It does not replace HIPAA, PCI DSS, or a state privacy law. It does not make a policy binder into a report. The opinion belongs to the CPA firm.
Does it apply to you?
It applies when a customer, an insurer, or a buyer asks for it, or when you decide a report will shorten the next sale. A firm that never handles someone else’s data usually has no reason to start.
A quick check:
- A contract or a questionnaire asks for SOC 2.
- You provide a service that holds or can affect customer data.
- You can name the system the report will describe.
If those are true, the next choice is Type I or Type II, and which categories the customer actually named. Do not add Privacy or Processing Integrity because they sound complete.
What you need in place
A report needs a system description, a control set mapped to the categories you chose, and evidence that those controls exist. Type II also needs evidence across the examination period.
- Owners for each control.
- Policies that match what the systems do.
- Access reviews, change records, and vendor reviews you can show.
- Logging, backup tests, and incident notes for the period the report covers.
- A CPA firm engaged before the period starts, if the goal is Type II.
How ALCON DTS helps
You keep the CPA firm and the system description. We run the controls on the systems we support and keep the evidence with you.
| SOC 2 element | What ALCON DTS provides |
|---|---|
| System picture | The identity, devices, email, network, and backups that belong in the description |
| Access | Unique accounts, multifactor authentication, and admin rights limited to the people who need them |
| Change and vendors | Records of material changes and the providers that can affect the system |
| Logging and restore | Logging on the managed environment, and backup and restore practice you can show |
| Evidence file | The settings, reviews, and test notes the CPA firm asks to sample |
| Readiness | A gap list before the examination period, so the period does not start on a control you cannot show |
The exact controls depend on the plan and any project work. The review shows what is in place and what would close a gap before a Type I date or a Type II period.
Need a clear picture of a SOC 2 ask? A review looks at who asked for the report, which categories they named, and what the systems can already show.
How it fits other rules
A security questionnaire often asks for the report or for the same controls. See our Security Questionnaires guide.
ISO 27001 is a certificate from a registrar. SOC 2 is a report from a CPA firm. A customer may ask for one, the other, or both.
PCI DSS still governs payment cards. HIPAA still governs patient information. Those duties do not fold into the SOC 2 opinion. See PCI DSS for Merchants and HIPAA Security Risk Analysis.
Frequently asked questions
Is SOC 2 a certification?
Who writes the opinion?
Should we start with Type I or Type II?
Does Security-only count?
How long is a Type II period?
Does a Microsoft 365 setup finish SOC 2?
Sources
- AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- Your CPA firm’s engagement letter for the report type and the categories
Talk with ALCON DTS
A review of your needs and growth plans looks at who asked for the report, which categories they named, and what the systems can already show. You keep the CPA firm. We run the controls and keep the evidence file with you.
Email: info@alcondts.com · Phone: 512-892-6900

