What it means
SOC 2 is an attestation performed by a licensed accounting firm against the AICPA trust services criteria — security, and optionally availability, processing integrity, confidentiality and privacy. A Type I report covers design at a point in time; Type II covers operating effectiveness over a period.
It is widely requested by enterprise buyers as a condition of purchase, which makes it a revenue matter for service providers as much as a control matter.
Where MyRISK fits
What we do about it
MyRISK is not an auditor and does not issue or prepare attestations. Where we are useful to an organisation carrying this burden is the decisions between audits — the exception granted to ship, the commitment made in a contract — which are what an enterprise security review asks about and what nobody has a record of.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.