---
title: "SOC 2, Definition | MedTech Terms"
description: "AICPA attestation report on a service organization's controls over Security, Availability, Processing Integrity, Confidentiality, and Privacy, the standard…"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/soc-2#term",
        "name": "SOC 2",
        "alternateName": [
          "SOC 2 Type I",
          "SOC 2 Type II",
          "AICPA SOC 2"
        ],
        "description": "SOC 2 (Service Organization Control 2) is an attestation report issued by an independent CPA firm under the AICPA SSAE 18 standard, evaluating a service organization's controls against one or more of the five Trust Services Criteria: Security (always required), Availability, Processing Integrity, Confidentiality, and Privacy. A SOC 2 Type I report attests to control design at a point in time; a Type II report attests to operating effectiveness over a period (typically 6-12 months) and is the much stronger artifact. SOC 2 is the de facto baseline trust report for SaaS, cloud, and processing-on-behalf-of-customer services in the U.S.",
        "url": "https://medtechterms.com/terms/soc-2",
        "termCode": "soc-2",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/soc-2#article",
        "headline": "SOC 2",
        "description": "AICPA attestation report on a service organization's controls over Security, Availability, Processing Integrity, Confidentiality, and Privacy, the standard SaaS trust artifact.",
        "url": "https://medtechterms.com/terms/soc-2",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/soc-2"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/soc-2#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "SOC 2, SOC 2 Type I, SOC 2 Type II, AICPA SOC 2, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "AICPA SOC 2 Examinations",
            "url": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2",
            "publisher": {
              "@type": "Organization",
              "name": "AICPA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "Trust Services Criteria",
            "url": "https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022",
            "publisher": {
              "@type": "Organization",
              "name": "AICPA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA - Cybersecurity for Medical Devices",
            "url": "https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hipaa#term",
            "name": "HIPAA",
            "alternateName": "HIPAA",
            "url": "https://medtechterms.com/terms/hipaa"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hitrust#term",
            "name": "HITRUST CSF",
            "alternateName": "HITRUST",
            "url": "https://medtechterms.com/terms/hitrust"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/fedramp#term",
            "name": "FedRAMP",
            "alternateName": "FedRAMP",
            "url": "https://medtechterms.com/terms/fedramp"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iso-27001#term",
            "name": "ISO/IEC 27001",
            "alternateName": "ISO 27001",
            "url": "https://medtechterms.com/terms/iso-27001"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hicp#term",
            "name": "Health Industry Cybersecurity Practices",
            "alternateName": "HICP",
            "url": "https://medtechterms.com/terms/hicp"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/samd#term",
            "name": "Software as a Medical Device",
            "alternateName": "SaMD",
            "url": "https://medtechterms.com/terms/samd"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "SOC 2",
            "item": "https://medtechterms.com/terms/soc-2"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  SOC 2

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

# SOC 2

AICPA attestation report on a service organization's controls over Security, Availability, Processing Integrity, Confidentiality, and Privacy, the standard SaaS trust artifact.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

SOC 2 (Service Organization Control 2) is an attestation report issued by an independent CPA firm under the AICPA SSAE 18 standard, evaluating a service organization's controls against one or more of the five Trust Services Criteria: Security (always required), Availability, Processing Integrity, Confidentiality, and Privacy. A SOC 2 Type I report attests to control design at a point in time; a Type II report attests to operating effectiveness over a period (typically 6-12 months) and is the much stronger artifact. SOC 2 is the de facto baseline trust report for SaaS, cloud, and processing-on-behalf-of-customer services in the U.S. 

What the regulation says

SOC 2 is a private attestation, not a regulatory requirement. HHS OCR doesn't certify or recognize SOC 2 for  [HIPAA](/terms/hipaa) compliance, though HHS guidance acknowledges SOC 2 reports as relevant evidence of recognized security practices under  [HICP](/terms/hicp)/PL 116-321. 

## What this means in practice

For MedTech, SOC 2 is the most common procurement requirement for any vendor handling PHI on behalf of a covered entity,  [SaMD](/terms/samd) platforms, AI/ML inference services,  [RPM](/terms/remote-patient-monitoring) clouds, clinical trial data services. A SOC 2 Type II report typically substitutes for a long custom security questionnaire and is required by Business Associate Agreements with hospitals. SOC 2 doesn't replace  [HIPAA](/terms/hipaa) compliance but is the standard way of demonstrating it operationally to customers. 

Common pitfalls

-   • Treating SOC 2 Type I as equivalent to Type II, Type I is design-only and provides little operational assurance. 
-   • Scoping SOC 2 to a subset of the product to make the audit easier, customers will check the scope statement and reject reports that exclude the systems they care about. 
-   • Confusing SOC 2 with HIPAA, SOC 2 includes some HIPAA-relevant controls but a SOC 2 report doesn't substitute for a Security Risk Analysis under 45 CFR 164.308. 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

FedRAMP(FedRAMP) 

U.S. government-wide program that standardizes security assessment, authorization, and continuous monitoring for cloud services sold to federal agencies.





](/terms/fedramp)[

Cybersecurity

Health Industry Cybersecurity Practices(HICP) 

Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.





](/terms/hicp)[

Cybersecurity

HIPAA(HIPAA) 

U.S. federal law governing the privacy and security of protected health information.





](/terms/hipaa)[

Cybersecurity

HITRUST CSF(HITRUST) 

Healthcare-focused certifiable security framework that consolidates HIPAA, NIST, ISO 27001, and other authorities into a unified control set.





](/terms/hitrust)

### More in Cybersecurity

· Same category 

[

Cybersecurity

ISO/IEC 27001(ISO 27001) 

International standard for information security management systems (ISMS), often required of MedTech vendors by enterprise customers.





](/terms/iso-27001)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

AICPA· 2 FDA· 1 

1.  [1 
    
    AICPA SOC 2 Examinations
    
    Verified 
    
    AICPA · aicpa-cima.com 
    
    
    
    ](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2)
2.  [2 
    
    Trust Services Criteria
    
    Verified 
    
    AICPA · aicpa-cima.com 
    
    
    
    ](https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022)
3.  [3 
    
    FDA - Cybersecurity for Medical Devices
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=soc-2)

Learn in 60 seconds

Card Lesson Quiz

AICPA attestation report on a service organization's controls over Security, Availability, Processing Integrity, Confidentiality, and Privacy, the standard SaaS trust artifact.

-   · A SOC 2 Type II report typically substitutes for a long custom security questionnaire and is required by Business Associate Agreements with hospitals. 
-   · SOC 2 doesn't replace HIPAA compliance but is the standard way of demonstrating it operationally to customers. 
-   · A SOC 2 Type I report attests to control design at a point in time; a Type II report attests to operating effectiveness over a period (typically 6-12 months) and is the much stronger artifact. 

Remember this

Watch out: Treating SOC 2 Type I as equivalent to Type II, Type I is design-only and provides little operational assurance.

Related terms

-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [HITRUST CSF(HITRUST) ](/terms/hitrust)
-   [FedRAMP(FedRAMP) ](/terms/fedramp)
-   [ISO/IEC 27001(ISO 27001) ](/terms/iso-27001)
-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [Software as a Medical Device(SaMD) ](/terms/samd)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [Threat Modeling ](/terms/threat-modeling)
-   [Penetration Testing ](/terms/pen-test)
-   [STRIDE Threat Model(STRIDE) ](/terms/stride)
-   [Hardware Root of Trust(HRoT) ](/terms/hardware-root-of-trust)
-   [Medjacking ](/terms/medjacking)
-   [NIST SP 800-53 / 800-171(NIST 800-53/171) ](/terms/nist-800-53)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)