Skip to main content
Category: SOC Reporting

SOC 2 Plus

Also known as: SOC 2+, Vendor Controls Attestation, SOC 2 Plus Additional Subject Matter
Simply put

SOC 2 Plus is an extended version of a standard SOC 2 examination that builds on the AICPA's SOC 2 reporting approach while also covering additional subject matter, such as controls mapped to other frameworks or requirements. Like a regular SOC 2, it results in an attestation report produced by an independent examiner rather than a certificate. It is often used so that a single engagement can address a service organization's SOC 2 controls together with other standardized criteria in one report.

Formal definition

SOC 2 Plus (also referred to as a Vendor Controls Attestation) is an examination built upon AICPA SOC 2 reporting principles that incorporates additional subject matter or criteria beyond the Trust Services Criteria alone, typically to demonstrate alignment with one or more supplementary frameworks within a single independent, standardized attestation. As with a conventional SOC 2 engagement, it is performed under the AICPA's attestation standards and produces a report (not a certification); it may be structured as a Type I (suitability of design at a point in time) or Type II (design and operating effectiveness over a defined review period, the length of which is set by scoping decisions). The report attests only to the controls, subject matter, and period covered, and does not by itself guarantee freedom from breaches; the specific additional criteria included and the mapping to other frameworks depend on the defined scope of the engagement. Any framework mappings within a SOC 2 Plus are typically partial, and inclusion of such subject matter does not by itself confer certification against those other frameworks.

Why it matters

Service organizations increasingly face overlapping compliance demands from customers, regulators, and internal governance functions, and responding to each with a separate audit is costly and duplicative. SOC 2 Plus addresses this by allowing a single independent examination to cover the AICPA's SOC 2 subject matter alongside additional criteria mapped to other frameworks. For a vendor whose customers ask for evidence against multiple standards, consolidating that evidence into one attestation report can reduce audit fatigue and streamline how assurance is communicated to enterprise buyers.

Because a SOC 2 Plus is built on SOC 2 reporting principles, it carries the same interpretive boundaries that compliance professionals must respect. It produces an attestation report from an independent examiner, not a certificate, and it attests only to the controls, subject matter, and period covered. A report does not guarantee that the service organization is free from security breaches, and the inclusion of additional framework criteria does not by itself confer certification against those frameworks. Readers evaluating a SOC 2 Plus report should therefore examine the defined scope closely to understand exactly which supplementary criteria were included and how completely they were addressed.

The value of a SOC 2 Plus depends heavily on the scoping decisions behind it. Any mapping between SOC 2 controls and other frameworks is typically partial, so a report should not be read as demonstrating equivalence or full coverage of the additional standards referenced. Used carefully, however, it can be an efficient way for a service organization to demonstrate alignment with multiple sets of requirements within one standardized, independently examined document.

Who it's relevant to

GRC and Compliance Managers
Compliance leaders who manage multiple, overlapping customer and regulatory requirements can use a SOC 2 Plus to consolidate assurance into a single engagement, reducing duplicative audits. They should pay close attention to how the additional criteria are scoped, since the framework mappings are typically partial and the report does not equate to certification against those other standards.
Service Organizations and Vendors
Vendors that must demonstrate alignment with more than one set of criteria to enterprise buyers may find a SOC 2 Plus (also called a Vendor Controls Attestation) an efficient way to address SOC 2 controls together with supplementary framework requirements in one standardized report, whether structured as a Type I or Type II examination.
Auditors and Independent Examiners
CPA examiners performing these engagements under the AICPA's attestation standards must carefully define the additional subject matter, establish how controls map to the supplementary criteria, and ensure the report clearly communicates the boundaries of what is attested, including that it produces a report rather than a certificate and covers only the defined scope and period.
Procurement and Vendor Risk Teams
Those evaluating third-party vendors should read a SOC 2 Plus report with attention to its defined scope, understanding that it attests only to the controls, subject matter, and period covered, does not guarantee freedom from breaches, and that inclusion of additional framework criteria does not by itself confer certification against those frameworks.

Inside SOC 2+

Base SOC 2 Examination
The foundational SOC 2 attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard, evaluating controls against the Trust Services Criteria. This can be structured as a Type I (suitability of design at a point in time) or Type II (design and operating effectiveness over a defined review period whose length is set by scoping decisions).
Additional Subject Matter or Criteria
The 'plus' component, in which the reporting entity incorporates one or more additional frameworks, criteria, or subject matter beyond the Trust Services Criteria into a single examination. This may include mappings to other standards or regulatory requirements, depending on scope and what the practitioner agrees to include.
Trust Services Criteria Foundation
The Security category (the Common Criteria) remains required, while Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on scope. SOC 2 Plus builds upon this foundation rather than replacing it.
Consolidated Report Structure
The output is still a SOC 2 report (an attestation, not a certification) that additionally addresses the supplementary criteria within the same examination, allowing an organization to demonstrate multiple areas of coverage in one document rather than commissioning separate assessments.
Practitioner-Defined Scope
The specific additional criteria included, and how they are tested and reported, are determined by scoping decisions agreed between the service organization and the CPA firm, and therefore vary from engagement to engagement.

Common questions

Answers to the questions practitioners most commonly ask about SOC 2+.

Is SOC 2 Plus a separate or higher-tier report than a standard SOC 2?
No. SOC 2 Plus is not a distinct report type or an elevated certification. It refers to a standard SOC 2 examination performed by a licensed CPA firm under the AICPA's SSAE 18 attestation standard, in which the scope is extended to address additional criteria drawn from another framework. The underlying engagement remains a SOC 2 attestation resulting in a report, not a certification, and it does not supersede or rank above a conventional SOC 2 report.
Does obtaining a SOC 2 Plus report mean an organization is also ISO 27001 certified?
No. A SOC 2 Plus report may map its controls against another framework's criteria, but such mapping is typically partial, and an attestation report is not equivalent to an ISO 27001 certification. ISO 27001 certification is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, following its own audit process. Satisfying the criteria covered in a SOC 2 Plus report does not automatically satisfy ISO 27001, and vice versa.
How do we define the scope of a SOC 2 Plus engagement?
Scope is set through scoping decisions made with the CPA firm. It typically begins with the required Security category (the Common Criteria) and any optional Trust Services Criteria selected as relevant, such as Availability, Processing Integrity, Confidentiality, or Privacy, and then adds the additional external criteria the report will address. The specific criteria included depend on the engagement, the applicable frameworks, and stakeholder needs, so scope varies from one examination to another.
Should we choose a Type I or Type II examination for a SOC 2 Plus report?
That choice depends on your objectives. A Type I examination assesses the suitability of the design of controls at a point in time, while a Type II examination assesses both design and operating effectiveness over a defined review period whose length is set through scoping decisions rather than fixed by the standard. Stakeholders requesting evidence of controls operating over time typically expect a Type II, but the appropriate choice depends on your scope and audience.
What limitations should we communicate to stakeholders about a SOC 2 Plus report?
A SOC 2 Plus report attests only to the controls and, for a Type II, the review period covered by the examination. It does not guarantee freedom from breaches, nor does it extend assurance beyond the criteria and boundaries defined in scope. Any additional criteria addressed reflect only what was included in that engagement, and the report does not represent certification against another framework.
How does a SOC 2 Plus engagement affect our audit preparation compared with a standard SOC 2?
Because the scope extends beyond the standard Trust Services Criteria to address additional external criteria, preparation typically involves evidencing controls against those added criteria as well. In most engagements this means coordinating documentation and mapping so that the CPA firm can evaluate the combined set. The exact effort depends on the additional criteria selected, existing control maturity, and the auditor's approach, so it varies by engagement.

Common misconceptions

SOC 2 Plus produces an ISO 27001 certification or otherwise satisfies ISO 27001 requirements.
SOC 2 Plus remains a SOC 2 attestation report issued under SSAE 18, not a certification. Even where mappings to ISO 27001 criteria are included, mapping between the frameworks is typically partial, and undergoing a SOC 2 Plus examination does not itself result in an accredited ISO/IEC 27001 certificate or automatically satisfy that standard's ISMS requirements.
The 'plus' additional criteria are standardized and always cover the same frameworks.
There is no single fixed set of additional criteria. What is included depends on scoping decisions agreed between the service organization and the CPA firm, so the supplementary subject matter varies from one engagement to another.
A SOC 2 Plus report guarantees the organization is secure and free from breaches across all covered areas.
The report attests only to the controls and, for a Type II, the period covered by the examination. It does not guarantee freedom from breaches and does not extend assurance beyond the criteria and scope defined for the engagement.

Best practices

Confirm early with the CPA firm which additional criteria will be incorporated and how they will be tested, since the 'plus' scope is defined by engagement scoping rather than a fixed standard.
Decide whether a Type I or Type II examination best fits your objectives, recognizing that Type II addresses operating effectiveness over a defined review period whose length is set during scoping.
Select the optional Trust Services categories (Availability, Processing Integrity, Confidentiality, Privacy) deliberately based on scope, keeping in mind that Security as the Common Criteria remains required.
Where the additional criteria reference another framework such as ISO 27001, treat any resulting mapping as partial and do not assume it substitutes for that framework's own certification or requirements.
Clearly document and communicate the boundaries of the report, including that it attests only to the controls and period covered and does not guarantee the absence of breaches.
Engage stakeholders who rely on the report to verify that the combined criteria genuinely meet their assurance needs before committing to a consolidated SOC 2 Plus examination.