SOC 2

SOC 2 is an attestation framework in which an independent auditor examines a service organization's controls against the AICPA Trust Services Criteria, security, availability, processing integrity, confidentiality, privacy. Type I assesses control design at a point in time; Type II tests operating effectiveness over an observation window, which is why Type II is what enterprise buyers ask for.

The report describes controls the organization defined for itself against the criteria, which is why two SOC 2 reports are not directly comparable. Reading one means reading the scope, the systems in it, the observation window, and the exceptions, rather than treating the existence of a report as the answer.

Readiness, evidence collection under way and no auditor engaged, is a legitimate position to be in and a different statement from an attestation. Describing one as the other is the misrepresentation the framework's own users watch for.

Two reports are not directly comparable, which is the single most useful thing to know when reading one. The organization defines its own controls against the Trust Services Criteria, so reading a report means reading the scope, the systems included, the observation window and the exceptions, rather than treating the existence of a report as the answer.

The scope section is where the gap between expectation and reality usually sits. A report can legitimately cover one product, one environment, or a subset of criteria, and a buyer who assumes it covers the system they are about to depend on is making an assumption the document does not support. Asking which systems are in scope is a fair question and a quick one.

Readiness, meaning evidence collection under way with no auditor engaged, is a legitimate position and a different statement from an attestation. Describing one as the other is the misrepresentation the framework's own users watch for, and the distinction is worth holding precisely in copy, since the words certified, attested and compliant each assert something a readiness posture has not earned. Keeping the claim aligned with what an independent party has actually examined is the same discipline an attestation requires of any signed statement.

The report describes controls rather than outcomes, which is why buyers pair it with technical evidence such as zero-PII architecture claims they can test.

PasskeyBridge verifies identity signals like these inside the request, with zero PII stored. See how the platform works or test the live API.