EdLaw org/aicpa/soc2/README.md

language: en · status: in-force · last checked: 2026-09-04

SOC 2 (System and Organization Controls 2)

A voluntary attestation framework defined by the AICPA (American Institute of Certified Public Accountants): an independent CPA reports on a service organization's controls against the Trust Services Criteria, whose five categories are Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA SOC 2 topic page). A Type II report covers the operating effectiveness of controls over a review period, rather than design at a point in time.

Sources are licensed — citation note

The governing documents (the Trust Services Criteria, TSP section 100, and the SOC 2 attestation guide) are AICPA publications sold commercially, so no verbatim criteria text is reproduced here and deep links are not available. Per METHODOLOGY.md, cite them precisely instead: AICPA, Trust Services Criteria (TSP §100, 2017, with revised points of focus 2022) and AICPA SOC 2® Guide. Facts on this page are limited to what the AICPA states publicly.

Applicability to EdTech

US districts increasingly request "SOC 2 Type II compliance reports" in procurement (as the pilot-district email does). SOC 2 is not a law and FERPA neither requires nor recognises audits or certifications (per the Department of Education's position); a SOC 2 Type II report functions as contractual/procurement evidence of security controls.

Sources