SOC 2 Plus
SOC 2 Plus is an extended version of a standard SOC 2 examination that builds on the AICPA's SOC 2 reporting approach while also covering additional subject matter, such as controls mapped to other frameworks or requirements. Like a regular SOC 2, it results in an attestation report produced by an independent examiner rather than a certificate. It is often used so that a single engagement can address a service organization's SOC 2 controls together with other standardized criteria in one report.
SOC 2 Plus (also referred to as a Vendor Controls Attestation) is an examination built upon AICPA SOC 2 reporting principles that incorporates additional subject matter or criteria beyond the Trust Services Criteria alone, typically to demonstrate alignment with one or more supplementary frameworks within a single independent, standardized attestation. As with a conventional SOC 2 engagement, it is performed under the AICPA's attestation standards and produces a report (not a certification); it may be structured as a Type I (suitability of design at a point in time) or Type II (design and operating effectiveness over a defined review period, the length of which is set by scoping decisions). The report attests only to the controls, subject matter, and period covered, and does not by itself guarantee freedom from breaches; the specific additional criteria included and the mapping to other frameworks depend on the defined scope of the engagement. Any framework mappings within a SOC 2 Plus are typically partial, and inclusion of such subject matter does not by itself confer certification against those other frameworks.
Why it matters
Service organizations increasingly face overlapping compliance demands from customers, regulators, and internal governance functions, and responding to each with a separate audit is costly and duplicative. SOC 2 Plus addresses this by allowing a single independent examination to cover the AICPA's SOC 2 subject matter alongside additional criteria mapped to other frameworks. For a vendor whose customers ask for evidence against multiple standards, consolidating that evidence into one attestation report can reduce audit fatigue and streamline how assurance is communicated to enterprise buyers.
Because a SOC 2 Plus is built on SOC 2 reporting principles, it carries the same interpretive boundaries that compliance professionals must respect. It produces an attestation report from an independent examiner, not a certificate, and it attests only to the controls, subject matter, and period covered. A report does not guarantee that the service organization is free from security breaches, and the inclusion of additional framework criteria does not by itself confer certification against those frameworks. Readers evaluating a SOC 2 Plus report should therefore examine the defined scope closely to understand exactly which supplementary criteria were included and how completely they were addressed.
The value of a SOC 2 Plus depends heavily on the scoping decisions behind it. Any mapping between SOC 2 controls and other frameworks is typically partial, so a report should not be read as demonstrating equivalence or full coverage of the additional standards referenced. Used carefully, however, it can be an efficient way for a service organization to demonstrate alignment with multiple sets of requirements within one standardized, independently examined document.
Who it's relevant to
Inside SOC 2+
Common questions
Answers to the questions practitioners most commonly ask about SOC 2+.