What does SOC 2 report mean on the CPA exam?
SOC 2 report. A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected. Restricted use. A SOC 1 covers controls over financial reporting instead.
Defined against AICPA SOC 2 Guide; TSP Section 100.
Which CPA exam sections use SOC 2 report?
SOC 2 report appears in the AUD section of the CPA exam.
Related terms
- trust services criteria: The AICPA's control criteria for a SOC 2 engagement, in five categories: security, availability, processing integrity, confidentiality and privacy.
- SOC 3 report: A general use report on the same trust services criteria as a SOC 2, without the system description or the tests and results.
- service organization: A third party whose processing affects a user entity's financial reporting, such as a payroll bureau or a claims processor.
- Trust Services categories: The five subject areas a SOC 2 can cover: security, availability, processing integrity, confidentiality and privacy.
- SOC 1 Type 2 report: A report covering the description, the suitability of design, and the operating effectiveness of controls over a period.
- processing integrity: One of the trust services categories: system processing is complete, valid, accurate, timely and authorized.