The encyclopedia · Software & IT · Strategic decision · 2010–2017
AICPA's SOC 2 made cloud security auditable and became the vendor-report standard
After SAS 70, AICPA's 2010 SSAE 16 created SOC 2: a CPA attestation of five trust criteria that SaaS buyers now ask every vendor for.
AICPA
The solution
As companies outsourced payroll processing and then cloud computing, they needed a trusted way to verify how vendors protected their data. The AICPA's SAS 70 audit had been used for this since 1992, but it was designed for financial-reporting controls, not security.
In April 2010 the AICPA announced SSAE 16, which created the SOC report family. SOC 2 was built for service providers and attests controls against the five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy — so a single CPA-issued report could speak for the whole system.
The framework won because it turned security due diligence into a commodity: instead of each customer running its own audit, one independent report answered everyone. It became the report service providers reach for, later updated under SSAE 18 and paired with a public-facing SOC 3.
Why it worked
- One independent attestation replaced every customer auditing the vendor
- Five clear criteria made reports comparable across vendors
- CPA independence gave the report credibility no self-assessment had
- Type I/Type II split let buyers match rigor to their risk
What can be applied
When buyers need to trust every vendor they outsource to, a standardized attestation beats a thousand one-off questionnaires: one auditor's report, one set of criteria, reusable across every customer.
Aftermath
SOC 2 became the de facto security report for SaaS and cloud vendors; SSAE 18 (2017) refreshed the underlying standard, and SOC for Cybersecurity and SOC for Supply Chain extended the same attestation model to new areas.
Sources
- The History of SOC 2
- Understanding AICPA Audits and Attestations: SSAE 16, SOC 1 vs. SOC 2, and Other Standards
spotted an error? The archive wants to know.