Cybersecurity glossary

Cybersecurity definition

What is SOC 2?

By Updated

Definition

An audit report, defined by the AICPA (the American Institute of CPAs) — SOC stands for System and Organization Controls — that evaluates a service organization's controls around security, availability, and related trust criteria. SOC 2 is the specific report enterprise SaaS customers most often require, as distinct from SOC 1's focus on financial reporting controls.

Where SOC 2 fits in the security landscape

These beginner lessons use this term while explaining the surrounding security control.

Use this definition as a baseline when reading category and product pages. Implementations, editions, and vendor terminology can differ; current product claims should be checked against the source-linked profile.

How definitions and product facts are maintained

Search Cyber Tool Stack

Jump to any tool, vendor, category, or glossary term.