SOC 2
AICPA attestation report on a service organization's controls over Security, Availability, Processing Integrity, Confidentiality, and Privacy, the standard SaaS trust artifact.
Definition
SOC 2 (Service Organization Control 2) is an attestation report issued by an independent CPA firm under the AICPA SSAE 18 standard, evaluating a service organization's controls against one or more of the five Trust Services Criteria: Security (always required), Availability, Processing Integrity, Confidentiality, and Privacy. A SOC 2 Type I report attests to control design at a point in time; a Type II report attests to operating effectiveness over a period (typically 6-12 months) and is the much stronger artifact. SOC 2 is the de facto baseline trust report for SaaS, cloud, and processing-on-behalf-of-customer services in the U.S.What this means in practice
For MedTech, SOC 2 is the most common procurement requirement for any vendor handling PHI on behalf of a covered entity, SaMD platforms, AI/ML inference services, RPM clouds, clinical trial data services. A SOC 2 Type II report typically substitutes for a long custom security questionnaire and is required by Business Associate Agreements with hospitals. SOC 2 doesn't replace HIPAA compliance but is the standard way of demonstrating it operationally to customers.- •Treating SOC 2 Type I as equivalent to Type II, Type I is design-only and provides little operational assurance.
- •Scoping SOC 2 to a subset of the product to make the audit easier, customers will check the scope statement and reject reports that exclude the systems they care about.
- •Confusing SOC 2 with HIPAA, SOC 2 includes some HIPAA-relevant controls but a SOC 2 report doesn't substitute for a Security Risk Analysis under 45 CFR 164.308.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsU.S. government-wide program that standardizes security assessment, authorization, and continuous monitoring for cloud services sold to federal agencies.
Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.
U.S. federal law governing the privacy and security of protected health information.
Healthcare-focused certifiable security framework that consolidates HIPAA, NIST, ISO 27001, and other authorities into a unified control set.
More in Cybersecurity
· Same categoryInternational standard for information security management systems (ISMS), often required of MedTech vendors by enterprise customers.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Primary references
3 sources- 1
AICPA SOC 2 ExaminationsVerifiedAICPAaicpa-cima.com
- 2
Trust Services CriteriaVerifiedAICPAaicpa-cima.com
- 3
FDA - Cybersecurity for Medical DevicesVerifiedFDAfda.gov
Inline markers like [1] jump to the matching reference above.