Framework guides

SOC 2: understand the assurance request

Clarify what a customer is asking for and what existing records can honestly support.

Reviewed 18 September 2026 · Prahari DPO

An assurance report, with a defined scope

AICPA describes SOC services as assurance reporting by CPAs. SOC 2 concerns controls relevant to security, availability, processing integrity, confidentiality or privacy, depending on the engagement scope.

AICPA & CIMA: System and Organization Controls services

Read the request carefully

Identify the service and system, criteria, report period, exceptions and customer expectations. Do not substitute a generic claim of “SOC compliance” for the actual report and its boundaries.

Prepare evidence without overclaiming

Organise existing policies, responsible owners and operating records. Mark gaps and planned work honestly. Independent examination and report issuance require an appropriate assurance engagement.

  • Confirm what may be shared and with whom.
  • Avoid disclosing unnecessary personal data or security detail.
  • Ensure the response describes the service the customer will actually receive.

Common questions

Is SOC 2 a privacy-law certificate?

No. An assurance report has its own scope and does not settle every legal obligation.

Can advisory preparation guarantee a report outcome?

No. Preparation and the independent examination are different activities; the examiner evaluates the relevant evidence.

Discuss the work you need

Agree the service, deliverables, responsibilities and fees before committing to an engagement.

Related reading

References

This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.

← Framework guides