SOC 2 glossary: 41 terms for compliance software buyers
Short answer
Short definitions of the terms that come up when you buy SOC 2 compliance software and prepare for an audit. Terms from a published standard link to the standard's page.
By the SOC 2 Vendor Compare ledger desk · Reviewed 2026-09-29 · Editorial assessment
Terms
- Attestation report
A report in which a CPA firm gives an opinion on a subject matter, such as a service organization's controls. A SOC 2 report is an attestation report, not a certificate.
Source: AICPA SOC suite of services · read 2026-09-29
- Auditor independence
The requirement that the auditor is free of relationships that could affect its judgment. Buyers should ask whether the auditor has any business arrangement with their compliance software vendor.
Related: How to choose a SOC 2 auditor, and what the platform's audit path changes
- Availability
The trust services category covering whether a system is available for operation and use as committed.
Related: The five SOC 2 trust services categories, explained
- BYOA (bring your own auditor)
Using an audit firm you contract directly rather than one the software vendor provides or recommends. Sprinto lists BYOA on its Foundation plan.
Related: Sprinto profile
- CMMC
Cybersecurity Maturity Model Certification, a US Department of Defense requirement for defense suppliers. Secureframe sells a Defense plan built for it.
Related: Secureframe profile
- Common control framework
A single set of internal controls mapped to several frameworks, so each control is set up once and reused. Sprinto describes one.
- Common criteria
The security criteria that apply to every SOC 2 report, covering areas such as governance, risk assessment, access, change management and monitoring.
Related: The five SOC 2 trust services categories, explained
- Compliance automation
Software that maps controls to frameworks, collects evidence from connected tools, runs tests and gives auditors access.
Related: What SOC 2 compliance automation software actually does
- Confidentiality
The trust services category covering information designated as confidential, from collection to disposal.
Related: The five SOC 2 trust services categories, explained
- Continuous monitoring
Automated tests that check connected systems against controls on a schedule and flag failures between audits.
- Control
A policy, procedure or technical measure that addresses a requirement, such as quarterly access reviews or encrypted backups.
- CPA firm
A licensed firm of certified public accountants. Only a CPA firm can issue a SOC 2 report.
Source: AICPA SOC suite of services · read 2026-09-29
- Cross-mapping
Linking one control to the matching requirements in several frameworks so the same evidence counts for each. Scytale states control cross-mapping across its 80+ frameworks.
- Evidence
Records that show a control operated, such as configuration exports, tickets, logs or training completions.
- Exception
A case in a Type II report where the auditor found that a control did not operate as described during the review period.
Related: SOC 2 Type I vs Type II: which report do you need first?
- Gap analysis
A comparison of current practices with the criteria of a framework, producing a list of what to fix before the audit.
Related: From readiness to report: the stages of a SOC 2 program
- GDPR
The EU General Data Protection Regulation on personal data. Scytale, Vanta, Drata, Secureframe and Thoropass list it.
- HIPAA
The US law covering the privacy and security of health information. It is a common second framework for health-tech companies.
- Integration
A connection between the compliance platform and another tool, such as a cloud provider or identity provider, used to collect evidence automatically.
Related: Counting integrations and frameworks on SOC 2 vendor pages
- ISMS
Information security management system, the set of policies, processes and controls that ISO/IEC 27001 requires an organization to establish and improve.
Source: ISO/IEC 27001:2022 · read 2026-09-29
- ISO/IEC 27001
The international standard for information security management systems. The current edition, ISO/IEC 27001:2022, is Edition 3, published in October 2022.
Source: ISO/IEC 27001:2022 · read 2026-09-29
- ISO/IEC 42001
The international management system standard for artificial intelligence. Scytale, Vanta and Drata list it among their frameworks.
- Management assertion
A written statement by the service organization's management about its system description and controls, included in the SOC 2 report.
- Observation period (review period)
The span of time over which a Type II report tests whether controls operated effectively. It is agreed with the auditor.
Related: SOC 2 Type I vs Type II: which report do you need first?
- PCI DSS
The Payment Card Industry Data Security Standard for organizations that handle card data. Scytale, Vanta, Drata, Secureframe and Thoropass list it.
- Peer review
The AICPA program under which CPA firms have their accounting and auditing practice reviewed by another firm. Ask whether your SOC 2 auditor is enrolled.
Related: How to choose a SOC 2 auditor, and what the platform's audit path changes
- Penetration test
An authorized simulated attack on your systems to find vulnerabilities. Scytale and Thoropass describe pen testing on their platforms.
Related: Pen testing inside SOC 2 platforms: what Scytale and Thoropass describe
- Privacy
The trust services category covering how personal information is collected, used, retained and disclosed.
Related: The five SOC 2 trust services categories, explained
- Processing integrity
The trust services category covering whether system processing is complete, valid, accurate and timely.
Related: The five SOC 2 trust services categories, explained
- Security questionnaire
A list of security questions a customer sends a vendor during procurement. Platforms offer automation that drafts answers from existing controls.
Related: Trust centers and security questionnaires after your SOC 2 report
- SOC 1
A SOC report on controls relevant to a customer's financial reporting.
- SOC 2
A SOC report on a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy.
Source: AICPA SOC suite of services · read 2026-09-29
Related: What is SOC 2? A plain-English guide for software buyers
- SOC 3
A general-use summary of a SOC 2 examination that can be shared publicly, with less detail than the SOC 2 report.
- System description
The part of a SOC 2 report that describes the services, infrastructure, software, people, procedures and data in scope.
- TPRM (third-party risk management)
Assessing and monitoring the security of your own vendors. Scytale, Vanta, Drata, Secureframe and Sprinto describe TPRM or vendor risk features.
- Trust center
A public page that shows an organization's security posture and lets prospects request documents such as the SOC 2 report.
Related: Trust centers and security questionnaires after your SOC 2 report
- Trust services criteria
The AICPA criteria used in SOC 2 examinations, grouped into security, availability, processing integrity, confidentiality and privacy.
Source: AICPA SOC suite of services · read 2026-09-29
- Type I report
A SOC 2 report on the design of controls as of a specific date.
Related: SOC 2 Type I vs Type II: which report do you need first?
- Type II report
A SOC 2 report on the design and operating effectiveness of controls over a review period.
Related: SOC 2 Type I vs Type II: which report do you need first?
- User access review
A periodic check that each person's access to systems is still appropriate. Drata and Secureframe list it as a plan feature or add-on.
- vCISO
A virtual chief information security officer, an outside security leader engaged part time. Vanta and Drata describe vCISO partners.