GetSOC2

SOC 2 glossary of terms

Definitions written for someone reading their first request list or their first report. Where a term is routinely misused, the entry says what it does not mean.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Four terms cause most of the confusion on a first SOC 2, and all four are below with what they do not mean. There is no such thing as SOC 2 certification, a Type 2 covers a period rather than a date, an exception is not a failure, and a carve-out is not a gap in your report. If you only read four entries, read those.

Reports and opinions

SOC 2
A report on controls at a service organisation relevant to security, availability, processing integrity, confidentiality or privacy, issued by a licensed CPA firm under AICPA attestation standards. It is a report and an opinion, not a certificate. Nobody is SOC 2 certified.
Type 1
An opinion on whether controls were suitably designed at a single point in time. Cheaper and faster, accepted by some buyers, and superseded the moment a Type 2 exists.
Type 2
An opinion on whether controls were suitably designed and operated effectively throughout a stated period. This is what enterprise buyers usually mean when they say SOC 2. The full comparison.
Unqualified opinion
The clean result. The auditor concludes the controls were suitably designed and, in a Type 2, operated effectively. Exceptions can be present in the detail and the opinion still be unqualified.
Qualified opinion
The auditor concludes that one or more controls did not achieve their objective. Not fatal, and it appears in the report where any reviewer will read it. What causes one.
Exception
An instance where a control did not operate as described. Common, expected in a first report, and recorded with your management response beside it. An exception is not a failed audit.
Management assertion
Your own written statement, signed by an officer, that the system description is accurate and the controls were suitably designed. It sits in the report ahead of the auditor's opinion.
System description
The section you write describing your service, boundaries, infrastructure, commitments and subservice organisations. Reviewers read it more closely than they read the opinion.
Bridge letter
A statement from your management covering the period between your report period end and today. Free, unaudited, and generally accepted for a gap of up to three months. What it says.

Scope and criteria

Trust Services Criteria
The criteria a SOC 2 is examined against, organised into five categories. Security is mandatory and the other four are optional. What each covers.
Common Criteria
The nine series of criteria, CC1 through CC9, that make up the Security category and underpin every SOC 2 regardless of what else you include.
Points of focus
Illustrative considerations published alongside the criteria. They are not requirements and an auditor does not test them individually.
Observation window
The period a Type 2 examines. Three months is the shortest most firms will accept for a first report and twelve is the usual steady state. It cannot be backdated. Choosing the length.
Subservice organisation
A third party performing controls necessary to meet your commitments. Your cloud host is the obvious one. Carve-out and inclusive methods.
Carve-out method
Excluding a subservice organisation's controls from your examination while naming the organisation and the controls you rely on it for. Normal, expected, and not a gap.
Inclusive method
Bringing a subservice organisation's controls inside your examination. Rare, expensive, and requires the third party's cooperation.
Complementary user entity controls
Controls your own customers must operate for your controls to work, listed in the report. Why they matter to your buyers.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Process and evidence

Readiness
The preparation work before an examination: gap assessment, policy authoring, control design, evidence collection. It cannot be performed by the firm that will audit you. What it costs.
Gap assessment
A structured comparison of what you do against what the criteria expect, producing a remediation list. $6,000 to $15,000 CAD as a standalone engagement in Canada.
Fieldwork
The period when the audit firm requests evidence, performs walkthroughs and tests samples. Usually three to six weeks of elapsed time.
Request list
Sometimes called a PBC list, for "prepared by client". The auditor's itemised evidence request. How completely you answer it on the first pass is the largest single driver of how long fieldwork takes.
Walkthrough
A conversation in which the auditor has the person who performs a control describe and demonstrate it. Send the person who does the work, not their manager.
Sample
The subset of occurrences an auditor tests for a control that operated many times. Sample sizes rise with the frequency of the control and the length of the window.
Independence
The rule preventing an audit firm from examining controls it designed, implemented or documented. It is why readiness and audit are two purchases from two providers.
Peer review
Periodic external review of a CPA firm's attestation practice. Ask to see the most recent result. The rest of the questions.

The Canadian terms no US glossary carries

PIPEDA
The federal Personal Information Protection and Electronic Documents Act, the baseline Canadian private-sector privacy statute. Applies to you independently of any audit. How it interacts with SOC 2.
Law 25
Quebec's reform of its private-sector privacy law. Adds a named person in charge, privacy impact assessments before transfers outside Quebec, a confidentiality incident register and data portability, with penalties reaching 4 percent of worldwide turnover. What it adds to a SOC 2 program.
Confidentiality incident
Quebec's term for unauthorised access, use, communication or loss of personal information. Broader than most breach definitions because loss of access counts.
PHIPA
Ontario's Personal Health Information Protection Act. If you handle health records for a clinic or hospital you are likely an agent under it, and its duties are not discharged by any assurance report.
Provincial PIPA
Alberta and British Columbia's private-sector privacy statutes, declared substantially similar to PIPEDA and displacing it for provincially regulated organisations in those provinces.
CSAE 3416
The Canadian standard for reporting on controls at a service organisation, published by CPA Canada. It is the domestic analogue of SOC 1 rather than of SOC 2, and a buyer asking for SOC 2 will not accept it instead.
PIIDPA
Nova Scotia's Personal Information International Disclosure Protection Act, which restricts storage of personal information outside Canada for public bodies and their service providers. Where residency rules actually come from.
Data residency
A commitment about where data is physically stored. Distinct from data sovereignty, which concerns which government can compel access to it. No Trust Services criterion mentions either.

Terms that are routinely misused

What people say against what is true
What you will hearWhat is actually the case
"We are SOC 2 certified"There is no certification. You hold a report containing an opinion. Why the vocabulary matters in a contract
"We passed our SOC 2"You received an unqualified opinion. There is no pass mark, and the report may still contain exceptions
"Our SOC 2 is valid for a year"A Type 2 covers a period that has ended. It does not expire, it ages, and reviewers start asking questions after about three months
"The platform makes us compliant"A platform collects evidence. It does not perform testing, form conclusions or sign anything
"SOC 2 covers our privacy obligations"It does not discharge PIPEDA, Law 25 or PHIPA, and the Privacy category only tests commitments you made yourself
"We need SOC 2 Type 3"There is no Type 3. SOC 3 exists and is a public summary with no detail. The three report families

Get quotes from Canadian firms

Describe your scope once and compare firms that price the same work.

Get matched
What does SOC 2 stand for?

System and Organization Controls, report type 2. It is an AICPA reporting framework for controls at a service organisation, examined against the Trust Services Criteria and issued as an opinion by a licensed CPA firm.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 opines on whether controls were suitably designed at one point in time. A Type 2 opines on whether they were suitably designed and operated effectively throughout a stated period, usually three to twelve months. A Type 2 is what most enterprise buyers mean.

What is a PBC list in a SOC 2 audit?

Prepared by client. It is the auditor's itemised list of evidence you have to produce. Answering it completely on the first pass is the single biggest factor in how long fieldwork takes and whether your firm bills above the quoted fee.

Is a SOC 2 exception the same as a failure?

No. An exception is one instance where a control did not operate as described. They are common and expected in a first report, and they appear with your management response beside them. The opinion can still be unqualified.

Is CSAE 3416 the Canadian version of SOC 2?

No. CSAE 3416 is the Canadian standard for reporting on controls at a service organisation and is the domestic analogue of SOC 1, which covers controls relevant to financial reporting. A buyer asking for SOC 2 will not accept it instead.