SOC 2, the website owner's edition

Your biggest customer just asked about SOC 2. The real question is about your website.

SOC 2 has 61 criteria. By our count, 53 of them touch your website, the server under it, the domain that points to it, or the email it sends. Here they are in plain English, with a 28-point self-check that shows where you stand before an auditor does.

It usually arrives as a spreadsheet.

Two hundred rows. "Do you enforce multi-factor authentication?" "Describe your backup and recovery testing." "Please attach your most recent SOC 2 Type II report."

The deal is waiting on it. And the first time you see it, most of it looks like it was written for a bank.

It wasn't written for a bank. It was written for anyone who holds other people's data. Your website does.

SOC 2 is a report that a licensed CPA firm writes after examining how a company protects the data it handles. The yardstick is a set of 61 Trust Services Criteria published by the AICPA, the US accounting profession's standards body. They're grouped into five categories: security, which every SOC 2 includes, plus availability, processing integrity, confidentiality and privacy, which a company adds when they matter to its customers.

The criteria were written for whole companies. Boards, hiring, org charts. But when we went through all 61, most of them came back to the same few places: your logins, your server, your domain, your email, your backups and the suppliers who touch them.

So we turned those into 28 plain yes-or-no questions, in seven layers. Tick the ones that are true today. It takes about ten minutes, and you might need to ask whoever looks after your hosting.

One thing first, because plenty of people get it wrong: nobody is "SOC 2 certified." A CPA firm examines you and writes a report. We're not a CPA firm and we don't write SOC 2 reports. What we do is make sure the website part of that report is something you're proud to hand over.

The SOC 2 website self-check

1. Who's in charge

An auditor's first questions aren't technical. Who owns this? Is it written down? How do you know it works? A website with no owner is a website nobody is protecting.

On a real site: the founder thinks the agency handles security. The agency thinks the hosting company does. The hosting company's contract says it's the customer's job. Nobody has looked in two years.

In our audit: Standard area 01 (scope and ownership), 02 (risk) and 10 (sound operations). We review the documents a SOC 2 auditor will ask for and tell you plainly which ones are missing.

2. Logins and access

This is where SOC 2 spends the most words, and where attackers spend the most time. Every login to your site, server, domain and email is a door.

On a real site: a freelancer who built the site in 2022 still has an admin account and the server password. They've moved on. Their email account hasn't been as careful.

In our audit: Standard area 03 (access) and 04 (configuration). We pull the real account lists from each system and scan your server from the outside.

3. Protecting the data

Data is safe in three states or none: moving, sitting still, and being thrown away. SOC 2 checks all three, plus whatever might be crawling around in it.

On a real site: the old server was "shut down" when the site moved. Nobody deleted it. It's still running, still unpatched, and still holds every customer record up to the day of the move.

In our audit: Standard area 04 (configuration), 06 (data protection) and 08 (monitoring). We test encryption from the outside and hunt for forgotten copies of your data.

4. Watching, responding and changing

A Type II report asks a harder question than "do you have controls?" It asks "did they work, every month, for the whole period?" This layer is where that proof comes from.

On a real site: a plugin update goes straight to the live site on a Friday afternoon. Checkout breaks. Nobody notices until Monday, and there's no record of what changed or how to undo it.

In our audit: Standard area 04 (patching), 05 (change control), 08 (monitoring) and 09 (incident response). Fortified Watch adds a month of evidence for this layer every month.

5. Suppliers and staying online

Your website is a chain of other people's services. SOC 2 asks whether you've checked each link, and whether the chain comes back if one breaks.

On a real site: the host has an outage. The site is down for two days. The backups? Stored by the same host, behind the same login, and down with everything else.

In our audit: Standard area 07 (suppliers) and 08 (backups and continuity). We test a restore with you instead of taking it on trust.

6. Confidential information and accurate processing

Two optional SOC 2 categories that matter to any site handling client files, quotes, orders or bookings. One asks if you keep secrets. The other asks if you get things right.

On a real site: the payment processor confirms a sale, but the website's webhook fails. The customer is charged, gets no order, no receipt and no reply. Then they dispute the charge.

In our audit: Standard area 05 (application security) and 06 (data protection), together with hands-on testing against the OWASP Top 10.

7. Privacy

Privacy is the biggest SOC 2 category, with 18 criteria. Nearly all of them start on your website, because that's where the personal data comes in.

On a real site: the privacy notice was copied from a template in 2019. Since then the site added a chat widget, two ad pixels and a session recorder. None of them are in the notice.

In our audit: Standard area 06 (data protection and privacy) and 09 (incident response). We compare your notice against every script your site actually loads.

0 / 28

Tick each statement that is true for your site.

Send my score for a free review

Your host's SOC 2 report has a page about you.

Big hosting and cloud companies have SOC 2 reports of their own. So it's tempting to think you're covered.

Read to the end. Nearly every one includes a section that lists what the customer must do for the host's security to work. Turn on two-step login for your account. Manage your own users. Patch your own server. Keep your own backups.

Your host secures the building. The doors you open are yours.

When your own auditor arrives, the host's report covers the data centre. Everything on that list falls to you. Most website owners have never seen it.

Now ask who checked.

A SOC 2 auditor won't take "the developer set that up" for an answer. They want evidence. And for a Type II report, they want months of it.

That's the trap. If you start collecting evidence the week the auditor arrives, you're six months late.

Our Readiness Review runs through every question on this page with you, reads your host's customer section, and gives you a gap list in the same order your auditor will ask. Our Certification Audit then tests your website, server, domain, DNS, email and backups hands-on, aligned with ISO/IEC 27001, and gives you a written report you can hand to your customer or your CPA firm. Fix the serious issues and you earn the Hacker Fortified Certified badge.

Then Fortified Watch keeps checking every month: scans, certificates, domain expiry, DNS changes, email records and backup freshness. Every month it runs is another month of evidence on file.

Nobody ever wished they'd started their SOC 2 evidence later.

Start a free written conversation

All 61 Trust Services Criteria

53 of 61 touch your website.

Our own count, from the point of view of a website and the services behind it. The labels are our plain-English summaries, not the AICPA's wording.

Criteria groupTouch your websiteSelf-check
CC1.1–CC1.5 · Tone at the topEthics, oversight, roles, skills, accountability. Mostly company-wide; roles and skills reach the site.2 of 5s1, s2
CC2.1–CC2.3 · CommunicationTelling staff the rules, and telling customers and the public how to reach you about security.2 of 3s2, s15
CC3.1–CC3.4 · Risk assessmentWhat could go wrong, including fraud and big changes.3 of 4s3
CC4.1–CC4.2 · Checking it worksRegular checks, and fixing what they find.2 of 2s4
CC5.1–CC5.3 · Controls and policiesChoosing safeguards for each risk and writing them down.2 of 3s2, s3
CC6.1–CC6.8 · Access and data protectionLogins, second login step, firewalls, encryption, malware, retiring old hardware.8 of 8s5–s12
CC7.1–CC7.5 · Monitoring and incidentsScanning, alerts, deciding what's an incident, responding and recovering.5 of 5s13–s15, s20
CC8.1 · Change managementTest, approve, record and roll back every change.1 of 1s16
CC9.1–CC9.2 · Disruption and suppliersSurviving an outage, and checking the companies you rely on.2 of 2s17, s20
A1.1–A1.3 · AvailabilityCapacity, backups and tested recovery.3 of 3s18–s20
C1.1–C1.2 · ConfidentialityKnowing what's confidential, and deleting it when it's time.2 of 2s21, s22
PI1.1–PI1.5 · Processing integrityOrders, payments and bookings that come out complete and correct. Matters most for shops and web apps.5 of 5s23, s24
P1.1–P8.1 · PrivacyNotice, consent, collection, retention, access requests, suppliers, breach notices and complaints.16 of 18s22, s25–s28

Questions

About SOC 2.

What is SOC 2?

SOC 2 is a report a licensed CPA firm writes after examining a company's controls against the Trust Services Criteria published by the AICPA. It covers security and, if the company chooses, availability, processing integrity, confidentiality and privacy. Customers ask for it to see whether they can trust a supplier with their data.

Can Hacker Fortified give me a SOC 2 report?

No. Only a licensed CPA firm can examine a company and issue a SOC 2 report. We're a website security firm. We test and fix the website, hosting, domain and email controls a SOC 2 auditor will ask about, and give you a written report you can share with your customer or your CPA firm. Our Hacker Fortified Certified badge is our own mark, not a SOC 2 report.

What's the difference between Type I and Type II?

A Type I report says your controls were designed properly on one date. A Type II report says they actually worked over a period, usually three to twelve months. Customers usually want Type II, which means the evidence has to exist months before the auditor arrives.

How many SOC 2 criteria apply to a website?

By our count, 53 of the 61 touch a website or the services behind it: the server, the domain and DNS, email, backups and suppliers. The other eight are company-wide governance, such as board oversight.

Do I need SOC 2 at all?

Only if your customers ask for it, usually larger companies buying software or services from you. Many smaller website owners can answer a customer's security questionnaire with an independent website audit report instead, at least until a full SOC 2 is worth the cost. Ask your customer what they'll accept.

Is SOC 2 the same as ISO 27001?

No, though they overlap heavily. ISO/IEC 27001 is an international standard you can be certified against by an accredited certification body. SOC 2 is an American attestation report written by a CPA firm. Work done for one goes a long way toward the other, which is why we map our standard to both.

Is Hacker Fortified affiliated with the AICPA?

No. We're an independent website security firm, not a CPA firm. This page is our own plain-English guide; it isn't AICPA content and isn't endorsed by the AICPA. The official Trust Services Criteria are published by the AICPA at aicpa-cima.com.

SOC 2® is a registered trademark of the American Institute of Certified Public Accountants. Criterion IDs refer to the AICPA's 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. The descriptions and ratings on this page are our own plain-English summaries, not the criteria text. Hacker Fortified does not perform SOC 2 examinations or issue SOC 2 reports.