
The workload
Every vendor 'SOC 2 available' claim traces back to an auditor testing an organization against a defined set of criteria, and the AICPA's own SOC suite of services page states, verified, that a SOC 2 engagement is 'an examination of controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.' That is the workload an outside CPA firm performs against whichever of those five categories the engagement scopes in, most commonly security alone or security plus one or two others.
What the documents show
Verified, from the same page: the current guide reflects 'the 2017 trust services criteria (with revised points of focus – 2022)' and was updated for 'SSAE No. 20 and SSAE No. 21' — the criteria behind today's SOC 2 reports dates to 2017, with a 2022 refresh to how evidence points are described, not a wholesale rewrite. The AICPA's own 2017 Trust Services Criteria (With Revised Points of Focus – 2022) page confirms this document's title and existence. The landing page also lists illustrative practice aids by name — a representation letter for 'SOC 2 Type 1' and a separate one for 'SOC 2 Type 2' — confirming AICPA materials treat these as two distinct report types, verified. The pages retrieved did not themselves spell out the design-versus-effectiveness distinction in the text available without the full purchased guide; industry practice built on this framework treats a Type 1 report as addressing control design at one point in time and a Type 2 as design plus operating effectiveness across a review period, a framing labelled editorial here rather than quoted AICPA copy.
The operating cost
AICPA publishes no price for a SOC 2 engagement on either page retrieved; the fee is set independently by whichever CPA firm performs the audit, and finding one requires requesting quotes directly, or from a compliance-automation vendor that arranges auditor introductions, two of which appear elsewhere in this batch. What the criteria document fixes, verified, is the subject matter tested — the five categories — not what that testing costs.
The stop condition
A Type 2 report only speaks to the review period it names; once that period ages past whatever window a customer considers current, the report stops functioning as evidence beyond that historical window, an editorial reading of the framework's point-in-time-versus-period structure rather than a stated expiration date. Neither page names a mandatory renewal cadence.
- Which of the five Trust Services Categories does a specific vendor's SOC 2 report actually cover, rather than assuming 'SOC 2' means all five?
- Is the report in question a Type 1 or a Type 2, and does the difference matter for what is being decided?
- How recently does the report's covered period end, and does that recency matter for the decision at hand?
The criteria document is the standard everything else in this batch's compliance-automation and audit-scope entries ultimately points back to. It defines what gets tested; it does not certify that any particular company passed, which is a separate document a buyer has to request and read for itself.
Sources & reading trail
States the five Trust Services Categories a SOC 2 examination covers, the 2017 criteria with 2022 revised points of focus, and lists distinct Type 1 and Type 2 practice aids.
Source published: Not established · Retrieved: 16 September 2026
Confirms the title, 2017 origin and 2022 revision of the criteria document underlying SOC 2 examinations.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.