Reference
SOC 2 glossary
Your first auditor meeting will contain about a dozen terms nobody explains, because to them the words are ordinary. These are the ones that actually come up, defined the way a CPA means them. Using them correctly is not vanity: it changes how the conversation goes, and it changes what you notice in your own report.
The engagement and the standards
- Attestation
- An engagement in which a CPA reports on subject matter that is the responsibility of another party. Management asserts; the CPA attests. This is why SOC 2 is not pass or fail and why "SOC 2 certified" does not exist.
- Examination
- The correct word for a SOC 2 engagement. Saying "examination" rather than "audit" is a small signal that you know how the CPA's world works.
- SSAE 18 AT-C 205
- The AICPA standard governing attestation engagements. When someone says "under SSAE 18", they mean the professional rules the examination follows.
- AICPA
- American Institute of Certified Public Accountants. Sets the standards and owns the Trust Services Criteria.
- Independence
- The rule that an auditor cannot examine controls they helped design or implement. It is the reason readiness and attestation are separate firms.
- Peer review
- Mandatory external review of a CPA firm's work quality. Peer review in good standing is a reasonable legitimacy check when selecting an auditor.
- Engagement letter
- The CPA firm's contract for the examination. It is between you and them, never through a readiness provider.
The roles
- Service organization
- The company being examined. If you are reading this, that is you. Shortened to "service org".
- Service auditor practitioner
- The CPA firm performing the examination. "Practitioner" is the SSAE 18 term for the same role.
- User entities
- Your customers, who read and rely on the report.
- User auditors
- The financial auditors of those customers, who may use your SOC report as evidence in their own work.
- Subservice organization
- A vendor you depend on to deliver your service. For an AWS-native startup this is usually AWS itself.
Report types
- SOC 1
- Controls relevant to your customers' financial reporting. A different report for a different purpose.
- SOC 2
- Controls relevant to security and operations, measured against the Trust Services Criteria. The one enterprise buyers ask for.
- SOC 3
- A short, public-facing summary of a SOC 2 with no detailed testing results. Postable on a website, unlike a SOC 2, which is shared under NDA.
- Type 1
- Reports on whether controls are suitably designed at a point in time. Faster, and what most startups get first. See Type 1 vs Type 2.
- Type 2
- Reports on whether controls operated effectively across a period, commonly three to twelve months. Requires evidence spanning that window.
Trust Services Criteria
- TSC
- Trust Services Criteria: the AICPA criteria a SOC 2 is evaluated against. Criteria, not controls. You design the controls.
- The five categories
- Security (mandatory), Availability, Processing Integrity, Confidentiality, Privacy. Security is the core of every report; the others are scoped in when your commitments require them.
- Common Criteria CC1 to CC9
- The criteria making up the Security category: control environment, communication, risk assessment, monitoring, control activities, logical and physical access (CC6), system operations (CC7), change management (CC8), and risk mitigation (CC9). When an auditor says "CC6", they mean access controls.
- Points of focus
- Sub-considerations under each criterion. Guidance to help you design controls, not a checklist you must satisfy one for one. Worth knowing, because treating them as mandatory inflates scope.
Evidence and testing
- PBC list request list
- Provided By Client, sometimes Prepared By Client: the itemized list of evidence the auditor asks you to hand over. Getting the format early is the single biggest efficiency win available. See the evidence checklist.
- IPE
- Information Produced by the Entity: any report or export you generate and hand over. Because you produced it, the auditor must be satisfied it is complete and accurate, so capture the source, query, and date at the moment of export.
- Control
- A specific safeguard, for example "MFA is enforced on all administrative accounts". Controls map to criteria.
- Test of controls
- The procedures the auditor performs to verify a control works.
- Population
- The complete set of items a sample is drawn from, such as every termination during the period. Completeness of the population is itself tested, and an incomplete one undermines every sample taken from it.
- Sampling
- Testing a subset rather than all of it, for example 25 of 300 access changes. Central to Type 2. The auditor selects; you do not.
- Exception deviation
- A control instance that failed a test. Enough exceptions produce a modified opinion. The most common cause is a control written more strictly than the company operates.
- Walkthrough
- A session where you demonstrate how a control works end to end while the auditor follows along. The mock audit is a rehearsal of exactly this.
- Fieldwork
- The period during which the auditor performs testing. Its length depends almost entirely on how ready your evidence is.
Inside the report
- Management assertion
- Management's formal written statement that the system description is accurate and controls are in place. A required section, and it is yours to sign, not your provider's.
- System description
- Your narrative of the system and its controls. A major section that the service organization writes. Readiness work scaffolds it; you own it.
- Opinion
- The auditor's formal conclusion. The whole point of the report.
- Unmodified unqualified, "clean"
- Controls are suitably designed and, for a Type 2, operating effectively. The goal.
- Qualified
- Mostly fine, with specific exceptions named. Not fatal, but customers read the exceptions.
- Adverse
- Controls are not suitably designed or not operating effectively.
- Disclaimer
- The auditor could not form an opinion, usually for lack of evidence.
Shared responsibility, for AWS teams
- Carve-out method
- The subservice organization (AWS) is described in your report but excluded from your auditor's testing, relying on AWS's own SOC report. The common default.
- Inclusive method
- The subservice organization's controls are included in the examination. Rare, and not something a startup arranges with AWS.
- CSOC
- Complementary Subservice Organization Controls: controls AWS is responsible for that you rely on.
- CUEC
- Complementary User Entity Controls: controls your customers must implement for your system to work as intended. Your report will list them, and AWS's report lists the ones you are expected to implement.
- AWS Artifact
- Where AWS publishes its own compliance reports, including its SOC 2, for download by account holders. Your auditor will expect you to have retrieved it.
Process and lifecycle
- Readiness assessment gap assessment
- Pre-examination evaluation of where you stand against the criteria. Ours is the $2,500 Gap Assessment, credited toward readiness.
- Remediation
- Fixing the gaps found. Independence is why the firm that remediates cannot be the firm that examines.
- Observation period examination period, window
- The time window a Type 2 covers. Three to twelve months, commonly three to six for a first report.
- Bridge letter gap letter
- A letter from management covering the gap between a report period's end and a customer's later reliance date. Routine, and usually free from your provider.
- Scope
- Which categories, which systems, and which period the report covers. Every scoping decision has a cost in criteria tested and evidence required.
Say this, not that
| Instead of | Say | Why it matters |
|---|---|---|
| "our audit" | "our examination" | Audit means something specific and different to a CPA |
| "passing the audit" | "a clean" or "unmodified opinion" | SOC 2 is not pass or fail |
| "SOC 2 certification" | "a SOC 2 Type 1 report" | There is no certificate. This is the most common error and reviewers notice |
| "the documents you need" | "your PBC list" | Names the actual artifact, which speeds the conversation |
| "the controls work" | "suitably designed" (Type 1) or "operating effectively" (Type 2) | The distinction is the entire difference between the two report types |
Have this conversation with someone who speaks both languages
We spend our days between AWS consoles and CPA request lists. The gap assessment tells you where you stand against 35 controls and what the examination will actually ask of you, in either vocabulary.
Book a 30-minute scoping callNo pitch deck. We look at your stack and tell you exactly what an audit would flag.