Overview
SOC 2 is a report on controls at a service organization, issued by an independent CPA firm under the attestation standards of the American Institute of Certified Public Accountants (AICPA). The CPA examines whether the organization's controls meet the Trust Services Criteria for security and, where the organization chooses, for availability, processing integrity, confidentiality, and privacy. Security is always in scope. The criteria in use today are the 2017 Trust Services Criteria with revised points of focus published in 2022.
The reports are written for customers, prospects, and their auditors, who need to judge the risk of handing data or operations to a vendor. A Type 1 report looks at whether controls are suitably designed at a single date, while a Type 2 report also tests whether the controls operated effectively over a period, often 6 to 12 months. Use is restricted. Customers usually receive a SOC 2 report under a non-disclosure agreement, and a shorter general use version, the SOC 3 report, can be posted publicly.
Canadian software, cloud, and managed service companies meet SOC 2 mostly through customer questionnaires and contract terms, especially when they sell into the United States. Canadian assurance standards have no SOC 2 standard of their own, so Canadian practitioners can report against the Trust Services Criteria under CSAE 3000, while some customers ask for a report under AICPA standards by name. Only licensed public accounting firms sign them. The Canadian Centre for Cyber Security lists AICPA SOC 2 Type II reports among the attestations it compares with ITSG-33 controls in its cloud service provider assessment process.
Who it applies to in Canada
Service organizations that host, process, or manage data or systems for customers, such as SaaS vendors, cloud and data centre providers, managed service providers, and payment or payroll processors.
Canadian service providers are asked for SOC 2 reports by enterprise and US customers during procurement. The Canadian Centre for Cyber Security also accepts SOC 2 Type II reports as evidence when it assesses cloud service providers for Government of Canada use.
Controls at a glance
The 2017 Trust Services Criteria have 33 common criteria for security, grouped CC1 to CC9, plus extra criteria for each of the 4 optional categories.
CC1 Control environment (5 criteria)
- Board and management oversight of internal control
- Commitment to integrity and ethical values
- Defined structures, reporting lines, and authority
- Hiring, training, and keeping competent people
- Holding people accountable for control duties
CC2 Communication and information (3 criteria)
- Using relevant, good quality information to run controls
- Communicating objectives and responsibilities internally
- Communicating with customers, vendors, and other outside parties
CC3 Risk assessment (4 criteria)
- Setting objectives clear enough to identify risks
- Identifying and analyzing risks to those objectives
- Considering the potential for fraud
- Assessing changes that could affect internal control
CC4 Monitoring activities (2 criteria)
- Ongoing or separate evaluations of controls
- Reporting deficiencies to the people who fix them
- Tracking corrective action to completion
CC5 Control activities (3 criteria)
- Choosing controls that reduce risk to acceptable levels
- General controls over technology
- Policies and procedures that put controls in place
CC6 Logical and physical access controls (8 criteria)
- Access security for software, infrastructure, and architecture
- Registering, authorizing, and removing users
- Role-based access and least privilege
- Restricting physical access to facilities and assets
- Secure disposal of data and equipment
- Protection against threats from outside the system boundary
- Controlling how data is transmitted and moved
- Preventing or detecting unauthorized or malicious software
CC7 System operations (5 criteria)
- Detecting configuration changes and new vulnerabilities
- Monitoring systems for anomalies and attacks
- Evaluating security events to decide if they are incidents
- Responding to incidents
- Recovering from incidents
CC8 Change management (1 criterion)
- Authorizing changes to infrastructure, data, and software
- Designing, testing, and approving changes before release
- Documenting and implementing changes in a controlled way
CC9 Risk mitigation (2 criteria)
- Planning for business disruption
- Assessing and managing vendor and business partner risk
- Considering insurance or other risk transfer
Availability (A1, 3 criteria)
- Managing capacity to meet demand
- Environmental protection, backups, and recovery infrastructure
- Testing recovery plans
Confidentiality (C1, 2 criteria)
- Identifying and protecting confidential information
- Disposing of confidential information when no longer needed
- Meeting confidentiality commitments made to customers
Processing integrity (PI1, 5 criteria)
- Defining and communicating processing specifications
- Complete and accurate inputs
- Complete, accurate, and timely processing
- Complete and accurate outputs
- Protecting stored items during processing
Privacy (P1 to P8, 18 criteria)
- Notice about privacy practices
- Choice and consent
- Collecting only what stated purposes need
- Use, retention, and disposal of personal information
- Access and correction by data subjects
- Disclosure to third parties and breach notification
- Quality of personal information
- Monitoring, enforcement, and handling complaints
Certification and assessment
Management prepares a description of its system and an assertion about its controls. The CPA firm examines the description and the controls against the Trust Services Criteria and issues an opinion, and in a Type 2 report it also describes the tests it ran and the results. There is no certificate or pass mark, so readers review the opinion, any exceptions, and the controls the customer is expected to run.
Dates to know
- 2018-10
- Canadian Centre for Cyber Security publishes its cloud service provider assessment process (ITSM.50.100), which accepts AICPA SOC 2 Type II reports
- 2023-09-30
- AICPA posts the current edition of the 2017 Trust Services Criteria with revised points of focus (2022)
In this hub
SOC 2 Trust Services Criteria explained
How the 2017 Trust Services Criteria are built, what the 9 common criteria cover, and how to choose the optional categories.
SOC 2 Type 1 vs Type 2 reports
The difference between a point-in-time Type 1 report and a period-of-time Type 2 report, and which one customers expect.
Preparing for a SOC 2 audit
Readiness, scoping, choosing a CPA firm, the observation period, and bridge letters for a first SOC 2 examination.
SOC 1, SOC 2, and SOC 3 compared
What each SOC report is for, who reads it, and the Canadian standards that cover similar engagements.
SOC 2 vs ISO 27001
How a SOC 2 attestation differs from ISO/IEC 27001 certification, and when Canadian organizations pursue one or both.
Resources
Official texts and free tools for SOC 2. Links open the publisher’s site.
- 2017 Trust Services Criteria (With Revised Points of Focus - 2022), AICPA and CIMA
- SOC 2: SOC for Service Organizations: Trust Services Criteria, AICPA and CIMA
- SOC 3: Trust Services Criteria for General Use Report, AICPA and CIMA
- Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Securityguidance
- Reports on Controls at Service Organizations FAQs, Chartered Professional Accountants of British Columbiaguidance
Need help? Browse the directory or read the guides.
References
- 2017 Trust Services Criteria (With Revised Points of Focus - 2022), AICPA and CIMA
- SOC 2: SOC for Service Organizations: Trust Services Criteria, AICPA and CIMA
- Reports on Controls at Service Organizations FAQs, Chartered Professional Accountants of British Columbia
- Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.