Definition · External Attack Surface Management
What is SOC 2?
SOC 2 (Service Organization Control 2) comes from the American Institute of Certified Public Accountants (AICPA). A service organisation describes the controls it operates, an independent CPA firm examines them against the Trust Services Criteria, and the firm issues a report containing an opinion. It is an attestation report, not a certificate — there is no SOC 2 logo or pass mark, and the report itself is the deliverable, usually shared under NDA.
Trust Services Criteria and report types
The criteria cover security, availability, processing integrity, confidentiality and privacy. Security — the common criteria — is always included; the others are added only if the organisation chooses to cover them, so two SOC 2 reports can have very different scopes.
- Type 1 — an opinion on whether controls are suitably designed at a point in time
- Type 2 — an opinion on whether they were also operating effectively across a review period, typically several months
Type 2 is what most customers ask for, because it tests operation over time rather than a snapshot.
Why external attack surface shows up in a SOC 2
The criteria are outcome-based rather than prescriptive, so nothing mandates a particular scanner. In practice, the controls organisations write down usually include boundary protection, change management and vulnerability identification and remediation — and an auditor testing those asks for evidence spanning the whole period: scan records, ticket trails, and timescales actually met.
That favours continuous monitoring over an annual burst. It also rewards knowing your own perimeter, since an asset discovery gap is the quiet way a control gets described accurately and applied to only part of the estate.
Related concepts
Compare with ISO 27001, a certifiable management-system standard, and Cyber Essentials, a UK technical baseline. SOC 1 covers financial reporting controls and SOC 3 is a public summary of a SOC 2. See also vulnerability management and security misconfiguration.