SOC 2, the website owner's edition
Your biggest customer just asked about SOC 2. The real question is about your website.
SOC 2 has 61 criteria. By our count, 53 of them touch your website, the server under it, the domain that points to it, or the email it sends. Here they are in plain English, with a 28-point self-check that shows where you stand before an auditor does.
It usually arrives as a spreadsheet.
Two hundred rows. "Do you enforce multi-factor authentication?" "Describe your backup and recovery testing." "Please attach your most recent SOC 2 Type II report."
The deal is waiting on it. And the first time you see it, most of it looks like it was written for a bank.
It wasn't written for a bank. It was written for anyone who holds other people's data. Your website does.
SOC 2 is a report that a licensed CPA firm writes after examining how a company protects the data it handles. The yardstick is a set of 61 Trust Services Criteria published by the AICPA, the US accounting profession's standards body. They're grouped into five categories: security, which every SOC 2 includes, plus availability, processing integrity, confidentiality and privacy, which a company adds when they matter to its customers.
The criteria were written for whole companies. Boards, hiring, org charts. But when we went through all 61, most of them came back to the same few places: your logins, your server, your domain, your email, your backups and the suppliers who touch them.
So we turned those into 28 plain yes-or-no questions, in seven layers. Tick the ones that are true today. It takes about ten minutes, and you might need to ask whoever looks after your hosting.
One thing first, because plenty of people get it wrong: nobody is "SOC 2 certified." A CPA firm examines you and writes a report. We're not a CPA firm and we don't write SOC 2 reports. What we do is make sure the website part of that report is something you're proud to hand over.
The SOC 2 website self-check
Your host's SOC 2 report has a page about you.
Big hosting and cloud companies have SOC 2 reports of their own. So it's tempting to think you're covered.
Read to the end. Nearly every one includes a section that lists what the customer must do for the host's security to work. Turn on two-step login for your account. Manage your own users. Patch your own server. Keep your own backups.
Your host secures the building. The doors you open are yours.
When your own auditor arrives, the host's report covers the data centre. Everything on that list falls to you. Most website owners have never seen it.
Now ask who checked.
A SOC 2 auditor won't take "the developer set that up" for an answer. They want evidence. And for a Type II report, they want months of it.
That's the trap. If you start collecting evidence the week the auditor arrives, you're six months late.
Our Readiness Review runs through every question on this page with you, reads your host's customer section, and gives you a gap list in the same order your auditor will ask. Our Certification Audit then tests your website, server, domain, DNS, email and backups hands-on, aligned with ISO/IEC 27001, and gives you a written report you can hand to your customer or your CPA firm. Fix the serious issues and you earn the Hacker Fortified Certified badge.
Then Fortified Watch keeps checking every month: scans, certificates, domain expiry, DNS changes, email records and backup freshness. Every month it runs is another month of evidence on file.
Nobody ever wished they'd started their SOC 2 evidence later.
All 61 Trust Services Criteria
53 of 61 touch your website.
Our own count, from the point of view of a website and the services behind it. The labels are our plain-English summaries, not the AICPA's wording.
| Criteria group | Touch your website | Self-check |
|---|---|---|
| CC1.1–CC1.5 · Tone at the topEthics, oversight, roles, skills, accountability. Mostly company-wide; roles and skills reach the site. | 2 of 5 | s1, s2 |
| CC2.1–CC2.3 · CommunicationTelling staff the rules, and telling customers and the public how to reach you about security. | 2 of 3 | s2, s15 |
| CC3.1–CC3.4 · Risk assessmentWhat could go wrong, including fraud and big changes. | 3 of 4 | s3 |
| CC4.1–CC4.2 · Checking it worksRegular checks, and fixing what they find. | 2 of 2 | s4 |
| CC5.1–CC5.3 · Controls and policiesChoosing safeguards for each risk and writing them down. | 2 of 3 | s2, s3 |
| CC6.1–CC6.8 · Access and data protectionLogins, second login step, firewalls, encryption, malware, retiring old hardware. | 8 of 8 | s5–s12 |
| CC7.1–CC7.5 · Monitoring and incidentsScanning, alerts, deciding what's an incident, responding and recovering. | 5 of 5 | s13–s15, s20 |
| CC8.1 · Change managementTest, approve, record and roll back every change. | 1 of 1 | s16 |
| CC9.1–CC9.2 · Disruption and suppliersSurviving an outage, and checking the companies you rely on. | 2 of 2 | s17, s20 |
| A1.1–A1.3 · AvailabilityCapacity, backups and tested recovery. | 3 of 3 | s18–s20 |
| C1.1–C1.2 · ConfidentialityKnowing what's confidential, and deleting it when it's time. | 2 of 2 | s21, s22 |
| PI1.1–PI1.5 · Processing integrityOrders, payments and bookings that come out complete and correct. Matters most for shops and web apps. | 5 of 5 | s23, s24 |
| P1.1–P8.1 · PrivacyNotice, consent, collection, retention, access requests, suppliers, breach notices and complaints. | 16 of 18 | s22, s25–s28 |
Questions
About SOC 2.
What is SOC 2?
SOC 2 is a report a licensed CPA firm writes after examining a company's controls against the Trust Services Criteria published by the AICPA. It covers security and, if the company chooses, availability, processing integrity, confidentiality and privacy. Customers ask for it to see whether they can trust a supplier with their data.
Can Hacker Fortified give me a SOC 2 report?
No. Only a licensed CPA firm can examine a company and issue a SOC 2 report. We're a website security firm. We test and fix the website, hosting, domain and email controls a SOC 2 auditor will ask about, and give you a written report you can share with your customer or your CPA firm. Our Hacker Fortified Certified badge is our own mark, not a SOC 2 report.
What's the difference between Type I and Type II?
A Type I report says your controls were designed properly on one date. A Type II report says they actually worked over a period, usually three to twelve months. Customers usually want Type II, which means the evidence has to exist months before the auditor arrives.
How many SOC 2 criteria apply to a website?
By our count, 53 of the 61 touch a website or the services behind it: the server, the domain and DNS, email, backups and suppliers. The other eight are company-wide governance, such as board oversight.
Do I need SOC 2 at all?
Only if your customers ask for it, usually larger companies buying software or services from you. Many smaller website owners can answer a customer's security questionnaire with an independent website audit report instead, at least until a full SOC 2 is worth the cost. Ask your customer what they'll accept.
Is SOC 2 the same as ISO 27001?
No, though they overlap heavily. ISO/IEC 27001 is an international standard you can be certified against by an accredited certification body. SOC 2 is an American attestation report written by a CPA firm. Work done for one goes a long way toward the other, which is why we map our standard to both.
Is Hacker Fortified affiliated with the AICPA?
No. We're an independent website security firm, not a CPA firm. This page is our own plain-English guide; it isn't AICPA content and isn't endorsed by the AICPA. The official Trust Services Criteria are published by the AICPA at aicpa-cima.com.
SOC 2® is a registered trademark of the American Institute of Certified Public Accountants. Criterion IDs refer to the AICPA's 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. The descriptions and ratings on this page are our own plain-English summaries, not the criteria text. Hacker Fortified does not perform SOC 2 examinations or issue SOC 2 reports.