Definition
SOC 2 is a report from an independent CPA on a service organization's system-level controls, developed by the AICPA. It gives customers information to assess the risks of outsourcing services. Buyers of HR and payroll software often request a SOC 2 report to evaluate how a vendor protects employee data.
Also known as: SOC 2 report, SOC2, System and Organization Controls 2
How it works
SOC is a suite of service offerings that CPAs may provide in connection with an organization's system-level controls. A SOC 2 engagement is an examination of controls at a service organization. The resulting report helps users assess and address the risks associated with outsourcing services.
SOC 2 reporting addresses controls relevant to security, availability, processing integrity, confidentiality, and privacy. The vendor chooses which of these categories fall within the scope of its report, so scope varies between vendors.
The AICPA promulgates the professional standards for SOC engagements and advises that SOC services be thoroughly evaluated by service organizations and CPA firms. For HR buyers, the practical step is to request the current report under a nondisclosure agreement, confirm which categories and systems are in scope, and review any exceptions noted by the auditor.
Example
A mid-size employer evaluating a payroll vendor requests its latest SOC 2 report. The security team checks that the payroll processing system is in scope and reads the auditor's noted exceptions before approving the contract.
Software that handles it
- HRIS Software
A shortlist of HRIS platforms ranked from verified product data, so you can compare employee-record depth, integrations and real pricing instead of marketing pages.
- Payroll Software
A shortlist of payroll platforms ranked from verified product data, so you can compare tax coverage, integrations and real pricing instead of vendor claims.
Related terms and guides
Frequently asked questions
What is a SOC 2 report?
A SOC 2 report is the result of an examination of controls at a service organization, performed by a CPA under AICPA standards. It helps customers assess the risks of outsourcing services to that organization, particularly where the vendor handles sensitive data.
What areas does SOC 2 cover?
SOC 2 reporting addresses controls relevant to security, availability, processing integrity, confidentiality, and privacy. The service organization determines which of these are included in its report, so buyers should check that the scope matches the systems and data they will use.
Is SOC 2 a certification?
It is an attestation report issued by an independent CPA firm, not a government license. The AICPA cautions that SOC services should be thoroughly evaluated and warns against promises of fast and easy reports, so buyers should review scope and auditor findings rather than rely on a logo.