System and Organization Controls (SOC)
System and Organization Controls (SOC) is a suite of examination and reporting services that CPAs provide to evaluate the controls a service organization uses to manage and safeguard its systems and data. The result of a SOC engagement is an independent report intended primarily for the service organization's customers and other users who rely on those controls. A SOC engagement gives assurance over how well an organization's controls function, but it is a point-in-time or period-specific assessment rather than a guarantee that no security incidents will occur.
System and Organization Controls (SOC) is an AICPA suite of service offerings under which a licensed CPA firm performs an attestation examination of system-level controls at a service organization and issues a report on those controls. SOC engagements assess controls relevant to the defined scope and, depending on the offering, produce reports intended for specified users; a SOC report reflects the findings of the underlying examination and attests only to the controls and the period or point in time covered. SOC is a family of distinct offerings (for example, SOC 1, SOC 2, and SOC 3) that differ in subject matter, applicable criteria, and intended audience, and a SOC report is an attestation deliverable rather than a certification.
Why it matters
Service organizations routinely handle systems and data on behalf of their customers, and those customers need a way to gain confidence in the controls protecting that information without auditing every vendor themselves. System and Organization Controls (SOC) reports address this need by having an independent, licensed CPA firm examine a service organization's controls and issue a report that customers and other reliant users can review. This shifts the burden away from every customer performing individual assessments and toward a single, standardized examination that multiple stakeholders can rely upon.
SOC reports carry weight because they are the product of an independent attestation examination rather than a self-assessment. The resulting report reflects the findings of the underlying examination and gives assurance over how well the organization's controls function. It is important to understand the boundaries of that assurance: a SOC report attests only to the controls and the point in time or period covered by the engagement. It is not a certification, and it does not guarantee that no security incident will occur or that the organization is free from risk outside the defined scope.
Because SOC is a family of distinct offerings, SOC 1, SOC 2, and SOC 3, among others, that differ in subject matter, applicable criteria, and intended audience, selecting and interpreting the correct report matters for procurement, vendor risk management, and audit reliance decisions. A user relying on the wrong SOC offering, or misreading a point-in-time report as an ongoing guarantee, can draw conclusions the report was never designed to support.
Who it's relevant to
Inside SOC
Common questions
Answers to the questions practitioners most commonly ask about SOC.