Home/SOC 2 glossary

Reference

SOC 2 glossary

Your first auditor meeting will contain about a dozen terms nobody explains, because to them the words are ordinary. These are the ones that actually come up, defined the way a CPA means them. Using them correctly is not vanity: it changes how the conversation goes, and it changes what you notice in your own report.

Updated 17 August 2026Grouped by topic~45 terms

The engagement and the standards

Attestation
An engagement in which a CPA reports on subject matter that is the responsibility of another party. Management asserts; the CPA attests. This is why SOC 2 is not pass or fail and why "SOC 2 certified" does not exist.
Examination
The correct word for a SOC 2 engagement. Saying "examination" rather than "audit" is a small signal that you know how the CPA's world works.
SSAE 18 AT-C 205
The AICPA standard governing attestation engagements. When someone says "under SSAE 18", they mean the professional rules the examination follows.
AICPA
American Institute of Certified Public Accountants. Sets the standards and owns the Trust Services Criteria.
Independence
The rule that an auditor cannot examine controls they helped design or implement. It is the reason readiness and attestation are separate firms.
Peer review
Mandatory external review of a CPA firm's work quality. Peer review in good standing is a reasonable legitimacy check when selecting an auditor.
Engagement letter
The CPA firm's contract for the examination. It is between you and them, never through a readiness provider.

The roles

Service organization
The company being examined. If you are reading this, that is you. Shortened to "service org".
Service auditor practitioner
The CPA firm performing the examination. "Practitioner" is the SSAE 18 term for the same role.
User entities
Your customers, who read and rely on the report.
User auditors
The financial auditors of those customers, who may use your SOC report as evidence in their own work.
Subservice organization
A vendor you depend on to deliver your service. For an AWS-native startup this is usually AWS itself.

Report types

SOC 1
Controls relevant to your customers' financial reporting. A different report for a different purpose.
SOC 2
Controls relevant to security and operations, measured against the Trust Services Criteria. The one enterprise buyers ask for.
SOC 3
A short, public-facing summary of a SOC 2 with no detailed testing results. Postable on a website, unlike a SOC 2, which is shared under NDA.
Type 1
Reports on whether controls are suitably designed at a point in time. Faster, and what most startups get first. See Type 1 vs Type 2.
Type 2
Reports on whether controls operated effectively across a period, commonly three to twelve months. Requires evidence spanning that window.

Trust Services Criteria

TSC
Trust Services Criteria: the AICPA criteria a SOC 2 is evaluated against. Criteria, not controls. You design the controls.
The five categories
Security (mandatory), Availability, Processing Integrity, Confidentiality, Privacy. Security is the core of every report; the others are scoped in when your commitments require them.
Common Criteria CC1 to CC9
The criteria making up the Security category: control environment, communication, risk assessment, monitoring, control activities, logical and physical access (CC6), system operations (CC7), change management (CC8), and risk mitigation (CC9). When an auditor says "CC6", they mean access controls.
Points of focus
Sub-considerations under each criterion. Guidance to help you design controls, not a checklist you must satisfy one for one. Worth knowing, because treating them as mandatory inflates scope.

Evidence and testing

PBC list request list
Provided By Client, sometimes Prepared By Client: the itemized list of evidence the auditor asks you to hand over. Getting the format early is the single biggest efficiency win available. See the evidence checklist.
IPE
Information Produced by the Entity: any report or export you generate and hand over. Because you produced it, the auditor must be satisfied it is complete and accurate, so capture the source, query, and date at the moment of export.
Control
A specific safeguard, for example "MFA is enforced on all administrative accounts". Controls map to criteria.
Test of controls
The procedures the auditor performs to verify a control works.
Population
The complete set of items a sample is drawn from, such as every termination during the period. Completeness of the population is itself tested, and an incomplete one undermines every sample taken from it.
Sampling
Testing a subset rather than all of it, for example 25 of 300 access changes. Central to Type 2. The auditor selects; you do not.
Exception deviation
A control instance that failed a test. Enough exceptions produce a modified opinion. The most common cause is a control written more strictly than the company operates.
Walkthrough
A session where you demonstrate how a control works end to end while the auditor follows along. The mock audit is a rehearsal of exactly this.
Fieldwork
The period during which the auditor performs testing. Its length depends almost entirely on how ready your evidence is.

Inside the report

Management assertion
Management's formal written statement that the system description is accurate and controls are in place. A required section, and it is yours to sign, not your provider's.
System description
Your narrative of the system and its controls. A major section that the service organization writes. Readiness work scaffolds it; you own it.
Opinion
The auditor's formal conclusion. The whole point of the report.
Unmodified unqualified, "clean"
Controls are suitably designed and, for a Type 2, operating effectively. The goal.
Qualified
Mostly fine, with specific exceptions named. Not fatal, but customers read the exceptions.
Adverse
Controls are not suitably designed or not operating effectively.
Disclaimer
The auditor could not form an opinion, usually for lack of evidence.

Shared responsibility, for AWS teams

Carve-out method
The subservice organization (AWS) is described in your report but excluded from your auditor's testing, relying on AWS's own SOC report. The common default.
Inclusive method
The subservice organization's controls are included in the examination. Rare, and not something a startup arranges with AWS.
CSOC
Complementary Subservice Organization Controls: controls AWS is responsible for that you rely on.
CUEC
Complementary User Entity Controls: controls your customers must implement for your system to work as intended. Your report will list them, and AWS's report lists the ones you are expected to implement.
AWS Artifact
Where AWS publishes its own compliance reports, including its SOC 2, for download by account holders. Your auditor will expect you to have retrieved it.

Process and lifecycle

Readiness assessment gap assessment
Pre-examination evaluation of where you stand against the criteria. Ours is the $2,500 Gap Assessment, credited toward readiness.
Remediation
Fixing the gaps found. Independence is why the firm that remediates cannot be the firm that examines.
Observation period examination period, window
The time window a Type 2 covers. Three to twelve months, commonly three to six for a first report.
Bridge letter gap letter
A letter from management covering the gap between a report period's end and a customer's later reliance date. Routine, and usually free from your provider.
Scope
Which categories, which systems, and which period the report covers. Every scoping decision has a cost in criteria tested and evidence required.

Say this, not that

Instead ofSayWhy it matters
"our audit""our examination"Audit means something specific and different to a CPA
"passing the audit""a clean" or "unmodified opinion"SOC 2 is not pass or fail
"SOC 2 certification""a SOC 2 Type 1 report"There is no certificate. This is the most common error and reviewers notice
"the documents you need""your PBC list"Names the actual artifact, which speeds the conversation
"the controls work""suitably designed" (Type 1) or "operating effectively" (Type 2)The distinction is the entire difference between the two report types

Have this conversation with someone who speaks both languages

We spend our days between AWS consoles and CPA request lists. The gap assessment tells you where you stand against 35 controls and what the examination will actually ask of you, in either vocabulary.

Book a 30-minute scoping call

No pitch deck. We look at your stack and tell you exactly what an audit would flag.