"SOC 2 certified" is a phrase that cannot be true — and what you receive instead
Ask a supplier for their SOC 2 certificate and you will be sent a PDF. It will not be a certificate, and the difference changes what the document tells you and what you may do with it.
On this page (8)
- What is actually performed
- Three documents, one binding
- The opinion, and the yardstick it uses
- The report is restricted, which is why the badge exists
- Four things a certificate would not tell you
- The firm that designed your controls cannot examine them
- Our own status, held to the same test
- What to send when a customer asks for your certificate
Ask a supplier for their SOC 2 certificate and you will be sent a PDF. It will not be a certificate, and the difference is not a technicality — it changes what you are allowed to do with the document, what it tells you, and which questions you still have to ask.
The AICPA's own documents are consistent about what gets issued. The guidelines governing the SOC logo say a service organisation may display it "provided it has had at least one of the following three SOC for Service Organizations reports issued by a licensed CPA". The description criteria say the CPA "expresses an opinion". Reports and opinions, throughout. The vocabulary for who does what in an ISO 27001 or SOC 2 programme is set out in who issues an ISO 27001 certificate, and what every other party produces; this piece is about the document at the end of a SOC 2 engagement.
What is actually performed
DC section 200, the AICPA's description criteria, states the engagement plainly: "The SOC 2 examination is performed in accordance with AT-C section 105, Concepts Common to All Attestation Engagements, and AT-C section 205, Assertion-Based Examination Engagements." AT-C 205 carries that title because SSAE No. 21 redrafted it, effective for reports dated on or after 15 June 2022; the same standard added AT-C section 206 for direct examinations.
The controls are evaluated against the 2017 Trust Services Criteria with revised points of focus, 2022, codified in TSP section 100. The CPA performing the work is called the service auditor — the description criteria note that the attestation standards would ordinarily call them a practitioner, and that the SOC 2 guide uses service auditor instead.
So: an examination, under attestation standards, against published criteria, by a licensed CPA firm. Every word of that describes an opinion engagement.
Three documents, one binding
DC section 200 paragraph .08 lists what arrives together — "the content of the SOC 2 report, the assertions made by management, and the service auditor's opinion, all of which are included in the report."
| In the report | Written by | What it is |
|---|---|---|
| The description of the system | Service organisation management | The narrative of the system, prepared against the description criteria in DC section 200 |
| Management's assertion | Service organisation management | Management's own written statement, included in the report alongside the description |
| The service auditor's report | The CPA firm | The opinion, and in a type 2 report the tests of controls and their results |
Who writes the description is a premise of the scheme rather than a convention, and paragraph .04 gives the reasoning: because management is "ultimately responsible for developing, implementing, and operating the service organization's system", management is "also responsible for developing and presenting in the SOC 2 report a description of the service organization's system." The service auditor then evaluates that description against the same published criteria.
Three documents, two signatories, and no third signature anywhere in the scheme.
The opinion, and the yardstick it uses
The service auditor expresses an opinion on three things, and DC section 200 paragraph .03 sets them out:
"a. Whether the description is presented in accordance with the description criteria
b. Whether the controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements would be achieved if controls operated effectively based on the applicable trust services criteria
c. In a type 2 examination, whether the controls operated effectively to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria"
Read (b) and (c) closely. The measure is reasonable assurance that the service organisation's own service commitments and system requirements would be or were achieved, based on the applicable trust services criteria. Part of the yardstick is what the organisation undertook to do.
Two suppliers can both hold an unmodified opinion having promised materially different things. A certificate would flatten that distinction, because a certificate is a binary object. A report does not, because it contains the description that says what was promised — and, in a type 2 report, the tests the service auditor ran and what those tests found.
Which type you are being shown decides how much of that is even in play. A type 1 opinion covers design at a point in time; a type 2 opinion covers operation across a period.
The report is restricted, which is why the badge exists
Paragraph .08 again, this time on who is meant to read it:
"A SOC 2 report is intended for use by those who have sufficient knowledge and understanding of the service organization, the services it provides, and the system used to provide those services, among other matters. … For that reason, management and the service auditor should agree on the intended users of the report (referred to as specified parties)."
Those specified parties, per the same paragraph, may include service organisation personnel, user entities, business partners subject to risks arising from interactions with the system, practitioners providing services to them, prospective user entities and business partners, and regulators — in every case "who have sufficient knowledge and understanding of such matters". The AICPA's logo guidelines put it in one line: "Use of a SOC 2® report is restricted to user entities, their auditors, and others who have the requisite understanding of the service organization."
There is a general-use report in the family, and the same guidelines describe it:
"If a service organization needs a report that it can distribute freely, it may ask the service auditor to also issue a SOC 3® report at the end of the SOC 2® examination. Unlike a SOC 2® report, a SOC 3® report does not include a description of the system, so the detailed controls within the system are not disclosed. In addition, the SOC 3® report does not include a description of the service auditor's tests of controls and the results thereof."
So the document that carries the detail is the one you cannot publish, and the document you can publish is the one with the detail removed. What a service organisation is permitted to put on a website is the AICPA's own logo — displayed "provided it has had at least one of the following three SOC for Service Organizations reports issued by a licensed CPA", and, under the September 2020 guidelines, hyperlinked to the AICPA's SOC page.
A badge that stands in for a restricted document is where "SOC 2 certified" comes from. It is shorthand invented on the marketing side of a scheme that produces opinions.
Four things a certificate would not tell you
Ask them of any supplier, and answer them about yourself before a customer does:
- Which trust services categories were in scope. A SOC 2 report can cover security, availability, processing integrity, confidentiality or privacy, in any combination. "SOC 2" alone names none of them.
- Type 1 or type 2. Design at a point in time, or operation over a period.
- Which period, and when it ended. A type 2 opinion is about a window that has closed. How long ago it closed is a fact about the evidence, not a detail.
- What the tests of controls found. A type 2 report contains them. DC section 200 treats deficiencies as an ordinary feature of the material: among the qualitative factors it lists for evaluating a description is "the extent to which identified deficiencies in the suitability of design or the operating effectiveness of controls contradict the disclosures about controls included in the description."
The description criteria are unusually direct about marketing language, incidentally. Paragraph .13 says a description is not presented in accordance with the criteria if it "contains statements that cannot be objectively evaluated (for example, advertising puffery)." That standard applies inside the report. It is worth applying to the sentence on the website that summarises it.
The firm that designed your controls cannot examine them
The AICPA Code of Professional Conduct treats certain activities as management responsibilities, and performing one for an attest client impairs independence outright — "the management participation threat would be so significant that no safeguards could reduce the threat to an acceptable level and independence would be impaired." The list at ET section 1.295.030 includes "accepting responsibility for designing, implementing, or maintaining internal control."
Where a firm does provide non-attest services to an attest client, ET section 1.295.040 requires the client to designate an individual with suitable skill, knowledge and experience to oversee the service, to "evaluate the adequacy and results of the services performed" and to "accept responsibility for the results of the services" — and the member must not assume management responsibilities.
That is the same structural rule as the one accredited certification bodies work under on the ISO 27001 side, arriving from a different profession and a different rulebook: the party that builds the controls is not the party that reports on them. It is why readiness work and the examination are bought separately.
Our own status, held to the same test
Security Brigade's SOC 2 Type II is in progress.
That sentence describes work, and nothing more. No opinion has been expressed on our controls, because an opinion in this scheme is expressed by a licensed CPA firm in a report, or it is not expressed at all. "In progress" is not an interim attestation, it does not carry partial assurance, and it should not be read as one — including when we are the ones writing it. If you are evaluating us, the four questions above are the right ones to ask, and the honest answer today is that the artefact they are about does not exist yet.
What to send when a customer asks for your certificate
Name the artefact. Tell them you hold a SOC 2 report, say which type and which categories, and say when the period ended. Agree the specified-parties list with your service auditor rather than treating distribution as an open question, and put the report out under the confidentiality terms that list implies. If the requester needs something they can circulate without restriction, that is what a SOC 3 report is for, and it is issued off the back of the same examination.
And if what they actually wanted was the word "certificate" — send the report anyway. It answers more than a certificate could.
Every clause reference, quotation and date above was checked against published text on 27 August 2026.
Continue reading
All articles →Why the firm that prepares you cannot be the firm that certifies you
No certification body may prepare you for its own audit, nor may any entity under its organisational control. Where a related body prepares you, it shall not certify you for two years.
Who issues an ISO 27001 certificate, and what every other party produces
An ISO 27001 programme produces four kinds of document and no party produces more than two. Who holds the certificate, the accreditation, and the Statement of Applicability.
The Indian law that names ISO 27001 — and what changes on 13 May 2027
One Indian rule names IS/ISO/IEC 27001 in its own text and deems an audited implementation compliance with the IT Act. A later Act omits the provisions it was made under.