Case D9FB10 · GRC · L2 Practitioner
SOC 2 Type I vs Type II
Practise as: Explain it · Interview
Interview questionA customer asks for your SOC 2. What is it, and what is the difference between a Type I and a Type II report?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- SOC 2 is an AICPA attestation by a CPA firm against the Trust Services Criteria; it is a report, not a certification.
- TSC: Security (Common Criteria, mandatory), plus optional Availability, Confidentiality, Processing Integrity, Privacy.
- Type I: controls suitably designed at a point in time. Type II: design and operating effectiveness over 3-12 months.
- Read the auditor opinion (unqualified vs qualified), exceptions in section 4, and scope/carve-outs of subservice orgs.
- Complementary User Entity Controls (CUECs) list what the customer must do for the controls to hold.
If the interviewer pushes back
- A vendor has a clean SOC 2 but AWS is carved out. What does that mean for your assurance and what else do you request?
- How would you respond to a Type II exception on access removal as the audited company?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.