Back to glossary

SOC 2

2 min read

In security governance, SOC 2 is a US attestation, based on the Trust Services Criteria, that reports on the controls a service organisation operates. It is what a US customer asks a Spanish software company to provide, and it usually arrives as a question alongside ISO 27001, which makes the two a natural comparison.

July 29, 2026
Compartir:

How it works

SOC 2 is an examination performed by an independent auditor, who reports on whether a service organisation’s controls meet the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality and privacy. It comes in two forms: a Type I report assesses whether the controls are suitably designed at a point in time, while a Type II report assesses whether they actually operated effectively over a period, typically several months, which is the version customers usually want. Unlike a certification against a fixed standard, SOC 2 reports against criteria and describes the controls the organisation chose, so no two reports look identical. It is the answer to a customer’s due-diligence question rather than a badge.

What goes wrong

The comparison with ISO 27001 is where the confusion sits. ISO 27001 certifies a management system, an ISMS, against a defined standard; SOC 2 attests to the operation of controls against criteria, oriented to the US market and framed as a report for customers rather than a certificate. Organisations often need both because different customers ask for different things, and the underlying controls overlap heavily even though the formats differ. The failure mode is the same as any attestation: a Type II report can describe controls that operated over the period and still leave a system exploitable, because the examination confirmed the control ran, not that it withstands attack.

Where this shows up in an audit

Several Trust Services Criteria expect evidence that security controls work, and technical testing supplies it: a penetration test demonstrates whether the controls the report describes actually resist attack, which strengthens the evidence behind the attestation. Because the same controls frequently serve an ISO 27001 ISMS and may touch obligations such as NIS2, one assessment can support several frameworks at once. We frame findings so they map to the criteria and the control described in the report. This is part of how testing produces evidence for a SOC 2 report.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.