Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Glossary

Definition · Allowed AI at work

SOC 2 Type II

SOC 2 Type II is an independent audit report issued by a CPA firm under AICPA standards. It tests whether a service organization's controls operated effectively over a period, usually 3 to 12 months. It measures controls against the AICPA Trust Services Criteria. It is an attestation report, not a certification, and it is not a HIPAA certification.

What SOC 2 Type II is

SOC 2 is a reporting framework from the American Institute of CPAs for companies that store or process customer data. An independent CPA firm examines the company's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is required in every SOC 2. The other four are chosen based on the service.

There are two types. A Type I report checks whether controls are suitably designed at a single point in time. A Type II report also tests whether those controls actually operated effectively across an observation period, using samples of real evidence. Type II is the stronger signal, because it shows the controls work day to day.

SOC 2 is not a HIPAA certification, and HHS does not recognize any HIPAA certification. A SOC 2 report does not replace a BAA or a HIPAA risk analysis. It is good evidence that a vendor runs mature security controls. Rivvi has a SOC 2 Type II report and also signs a HIPAA BAA.

Questions

SOC 2 Type II, answered

SOC 2 Type I vs Type II: what is the difference?
Type I evaluates whether controls are designed properly at one point in time. Type II evaluates design and also tests whether the controls operated effectively over a period, often 3 to 12 months. Buyers usually prefer Type II because it shows sustained practice, not just documented intent.
Is SOC 2 the same as HIPAA compliance?
No. SOC 2 is a voluntary AICPA audit of security controls. HIPAA is a federal law with specific Privacy, Security, and Breach Notification Rules. A vendor can have SOC 2 and still fail HIPAA duties. For PHI you need a signed BAA, whatever audits the vendor holds.
What are the five trust services criteria?
Security, availability, processing integrity, confidentiality, and privacy. Security, also called the common criteria, is mandatory. Availability covers uptime commitments. Processing integrity covers complete and accurate processing. Confidentiality covers protecting designated confidential data. Privacy covers how personal information is collected, used, kept, and disposed of.
How do I get a vendor's SOC 2 report?
Ask the vendor. SOC 2 reports are restricted-use documents, so vendors usually share them under an NDA or through a trust portal. Check the report period, the criteria in scope, and any exceptions the auditor found. Also ask for a bridge letter covering the time since the period ended.

Try it on your own data today.

Free to start. Most teams are using it the same day.