SOC 2 for service organizations: the Trust Services Criteria
May 2026 · 6 min read
SOC 2 is an assurance framework defined by the AICPA for service organizations that store, process or transmit customer data. Rather than a certificate, it results in an independent auditor's report on the design (Type I) and operating effectiveness (Type II) of an organization's controls.
The five Trust Services Criteria
SOC 2 is built on five Trust Services Criteria: Security (always in scope), plus Availability, Confidentiality, Processing Integrity and Privacy, included based on what the organization commits to its customers.
Security — the 'common criteria' — covers governance, access control, change management, risk, monitoring and incident response, much of which overlaps with ISO 27001 Annex A.
SOC 2 vs ISO 27001
The two are complementary. ISO 27001 certifies a management system against an international standard; SOC 2 produces an attestation report tailored to the criteria a service organization commits to. Many providers pursue both, and the underlying controls and evidence largely overlap.
If your customers are predominantly North American, SOC 2 is often the first ask; for international and Gulf markets, ISO 27001 frequently leads. A shared control library lets you satisfy both efficiently.
Preparing for an examination
Define your system boundary and the criteria in scope, implement the controls, and — crucially for a Type II — operate them consistently over the review period while retaining evidence. Confirm current requirements with your auditing firm, as professional guidance evolves.
This article is general guidance, not legal advice. Regulations evolve — confirm current requirements with the relevant authority (NCA / SDAIA in KSA; DESC / the UAE Data Office in the UAE). Questions? info@grclens.net.
Keep reading
Cyber governance in the Gulf: how KSA and the UAE set the pace
A regional map of the regulators and frameworks shaping cybersecurity governance across Saudi Arabia and the UAE — and what they have in common.
Security assurance in Saudi Arabia: making NCA-ECC stick
Implementing the Essential Cybersecurity Controls is only half the job. Sustaining assurance — proving controls keep working — is where programs succeed or fail.
Cyber governance in Dubai: DESC ISR and the UAE IA Standards
Dubai government entities and their suppliers operate under the DESC Information Security Regulation. Here's how it connects to the wider UAE assurance landscape.