SOC 2

SOC 2 for service organizations: the Trust Services Criteria

May 2026 · 6 min read

SOC 2 is an assurance framework defined by the AICPA for service organizations that store, process or transmit customer data. Rather than a certificate, it results in an independent auditor's report on the design (Type I) and operating effectiveness (Type II) of an organization's controls.

The five Trust Services Criteria

SOC 2 is built on five Trust Services Criteria: Security (always in scope), plus Availability, Confidentiality, Processing Integrity and Privacy, included based on what the organization commits to its customers.

Security — the 'common criteria' — covers governance, access control, change management, risk, monitoring and incident response, much of which overlaps with ISO 27001 Annex A.

SOC 2 vs ISO 27001

The two are complementary. ISO 27001 certifies a management system against an international standard; SOC 2 produces an attestation report tailored to the criteria a service organization commits to. Many providers pursue both, and the underlying controls and evidence largely overlap.

If your customers are predominantly North American, SOC 2 is often the first ask; for international and Gulf markets, ISO 27001 frequently leads. A shared control library lets you satisfy both efficiently.

Preparing for an examination

Define your system boundary and the criteria in scope, implement the controls, and — crucially for a Type II — operate them consistently over the review period while retaining evidence. Confirm current requirements with your auditing firm, as professional guidance evolves.

This article is general guidance, not legal advice. Regulations evolve — confirm current requirements with the relevant authority (NCA / SDAIA in KSA; DESC / the UAE Data Office in the UAE). Questions? info@grclens.net.