Fig. 01 · Glossary
SOC 2
Also known as SOC 2 Type II, System and Organization Controls 2
Definition
SOC 2 is an independent attestation of controls against the AICPA Trust Services Criteria. For technology companies, SOC 2 affects enterprise sales, customer trust, security maturity, and buyer diligence. The operating risk is not the report itself but whether the underlying controls are real, repeatable, and maintained.
SOC 2 should reduce sales friction, not create compliance theater. Buyers and enterprise customers care whether access control, change management, incident response, vendor management, and control records actually operate.
In post-acquisition work, SOC 2 gaps often reveal deeper issues: unmanaged identities, weak deployment controls, undocumented systems, and unclear ownership of security decisions.
Human Renaissance glossary · operator-grade definitions · Research methodology
