# soc2

Source: https://startwithidentity.com/glossary/soc2/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

A report issued by an auditor against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 is a point-in-time design; Type 2 covers an operating period, typically 6-12 months.

SOC 2 is the report every B2B buyer asks for, and its identity content is predictable: access provisioning and removal, periodic access review, MFA, and logging. A Type 2 covering a real observation window is the one that means something, since a Type 1 only says the design existed on a given day. Read the exceptions section, not the opinion letter.

See also: [compliance guides](https://startwithidentity.com/guides/compliance/), [access certification](https://startwithidentity.com/glossary/access-certification/), [deprovisioning](https://startwithidentity.com/glossary/deprovisioning/), [B2B SaaS identity](https://startwithidentity.com/verticals/b2b-saas/)
