SOC 2 (System and Organization Controls 2)
A voluntary attestation framework defined by the AICPA (American Institute of Certified Public Accountants): an independent CPA reports on a service organization's controls against the Trust Services Criteria, whose five categories are Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA SOC 2 topic page). A Type II report covers the operating effectiveness of controls over a review period, rather than design at a point in time.
Sources are licensed — citation note
The governing documents (the Trust Services Criteria, TSP section 100, and the SOC 2 attestation guide) are AICPA publications sold commercially, so no verbatim criteria text is reproduced here and deep links are not available. Per METHODOLOGY.md, cite them precisely instead: AICPA, Trust Services Criteria (TSP §100, 2017, with revised points of focus 2022) and AICPA SOC 2® Guide. Facts on this page are limited to what the AICPA states publicly.
Applicability to EdTech
US districts increasingly request "SOC 2 Type II compliance reports" in procurement (as the pilot-district email does). SOC 2 is not a law and FERPA neither requires nor recognises audits or certifications (per the Department of Education's position); a SOC 2 Type II report functions as contractual/procurement evidence of security controls.
Related
- NIST CSF — the framework SOC 2 controls are often mapped against in US procurement
- SDPC NDPA — the contractual instrument SOC 2 reports typically accompany
Sources
- AICPA & CIMA — SOC 2 topic page
- AICPA, Trust Services Criteria (TSP §100) — licensed publication, no public link