Quick answer
This glossary gives plain-English definitions of the compliance and security audit terms you will meet while pursuing SOC 2 and related frameworks, from Trust Services Criteria and evidence to Type I vs Type II reports and risk registers. Use it as a quick reference alongside our SOC 2 guide and documentation.
Compliance and security audit terms
Definitions are listed alphabetically. Each term links back to the concepts it relates to.
- AICPA
- The American Institute of Certified Public Accountants, the body that created and maintains the SOC reporting framework.
- Attestation
- A formal engagement in which a licensed CPA firm examines and reports an opinion on a company's controls. SOC 2 is an attestation, not a certification.
- Audit
- An independent examination of a company's controls against a defined set of criteria, resulting in a report.
- Auditor
- The independent, licensed CPA firm that tests a company's controls and issues the SOC report.
- Availability
- A Trust Services Criterion covering whether a system is operational and accessible in line with its commitments and SLAs.
- Common Criteria
- The mandatory Security criteria that every SOC 2 report must cover, regardless of which optional criteria are added.
- Confidentiality
- A Trust Services Criterion covering the protection of information designated as confidential, such as business secrets.
- Control
- A safeguard or process that reduces risk, such as enforcing multi-factor authentication or reviewing access quarterly.
- DPDPA
- India's Digital Personal Data Protection Act, which governs how personal data is collected and processed.
- EU AI Act
- The European Union's risk-based regulation for AI systems, setting obligations that scale with a system's risk tier.
- Evidence
- Proof that a control operates, such as configuration exports, access lists, logs, or tickets. Auditors test controls by reviewing evidence.
- Gap assessment
- A review that compares your current controls against a framework's requirements to identify what is missing before an audit.
- GDPR
- The EU General Data Protection Regulation, which sets rules for protecting the personal data of people in the EU.
- HIPAA
- A US law that sets requirements for protecting sensitive healthcare information.
- Inherent risk
- The level of a risk before any controls are applied to reduce it.
- Integration
- A connection between a compliance platform and another tool that lets the platform pull evidence automatically through an API.
- ISO 27001
- An international standard for building and operating an information security management system (ISMS).
- Penetration test
- A simulated attack used to find security weaknesses. It is often expected as part of a SOC 2 program.
- Privacy
- A Trust Services Criterion covering how personal information is collected, used, retained, and disposed of per a privacy notice.
- Processing integrity
- A Trust Services Criterion covering whether system processing is complete, accurate, timely, and authorized.
- Residual risk
- The risk that remains after controls have been applied to reduce the inherent risk.
- Risk assessment
- The process of identifying and evaluating risks to your systems and data. It is a required control for SOC 2 and ISO 27001.
- Risk register
- A living record of identified risks, including each risk's owner, score, treatment, and the controls that address it.
- Security
- The mandatory Trust Services Criterion covering protection against unauthorized access, disclosure, and misuse. Also called the Common Criteria.
- SOC 1
- A SOC report on controls at a service organization that are relevant to its clients' financial reporting.
- SOC 2
- A SOC report on controls for security, availability, processing integrity, confidentiality, and privacy. The common security standard for B2B SaaS.
- SOC 3
- A short, general-use version of a SOC 2 report that can be shared publicly as a trust seal.
- SSAE 18
- The attestation standard under which SOC audits are performed by CPA firms.
- Trust Services Criteria (TSC)
- The five categories SOC 2 is scoped around: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Only Security is mandatory.
- Type I
- A SOC report on whether controls are suitably designed at a single point in time.
- Type II
- A SOC report on whether controls operated effectively over a period, usually 3 to 12 months.
- Vendor risk
- The risk introduced by third-party vendors and subprocessors that handle your data or systems.

