EN
Back to the archive

The encyclopedia · Software & IT · Strategic decision · 2010–2017

AICPA's SOC 2 made cloud security auditable and became the vendor-report standard

After SAS 70, AICPA's 2010 SSAE 16 created SOC 2: a CPA attestation of five trust criteria that SaaS buyers now ask every vendor for.

AICPA

The solution

As companies outsourced payroll processing and then cloud computing, they needed a trusted way to verify how vendors protected their data. The AICPA's SAS 70 audit had been used for this since 1992, but it was designed for financial-reporting controls, not security.

In April 2010 the AICPA announced SSAE 16, which created the SOC report family. SOC 2 was built for service providers and attests controls against the five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy — so a single CPA-issued report could speak for the whole system.

The framework won because it turned security due diligence into a commodity: instead of each customer running its own audit, one independent report answered everyone. It became the report service providers reach for, later updated under SSAE 18 and paired with a public-facing SOC 3.

Why it worked

  • One independent attestation replaced every customer auditing the vendor
  • Five clear criteria made reports comparable across vendors
  • CPA independence gave the report credibility no self-assessment had
  • Type I/Type II split let buyers match rigor to their risk
What it achievedMake an auditor certify the vendor's controlsneat

What can be applied

When buyers need to trust every vendor they outsource to, a standardized attestation beats a thousand one-off questionnaires: one auditor's report, one set of criteria, reusable across every customer.

Aftermath

SOC 2 became the de facto security report for SaaS and cloud vendors; SSAE 18 (2017) refreshed the underlying standard, and SOC for Cybersecurity and SOC for Supply Chain extended the same attestation model to new areas.

Sources

spotted an error? The archive wants to know.

Related cases