SOC 2 availability evidence
What a System and Organization Controls (SOC) 2 report with the Availability category covers, who issues it and how to build the evidence your US customers ask for.
Updated:
What a SOC 2 report is
A SOC 2 report is the result of an examination performed by a certified public accountant (CPA) firm against the Trust Services Criteria of the American Institute of Certified Public Accountants (AICPA). The SOC 2 report is issued by the CPA firm after its examination. Your company prepares the system, the controls and the evidence that the examination looks at.
Security, through the common criteria, is part of every SOC 2 report; Availability is one of the additional categories that can be added, along with Processing Integrity, Confidentiality and Privacy.
The report is a type 1 or a type 2 report: ask your customer which one it expects.
The three availability criteria
The Availability category has three criteria, from the AICPA's 2017 Trust Services Criteria (TSP Section 100), with revised points of focus from 2022:
A1.1 Capacity
The entity maintains, monitors and evaluates its current processing capacity and the use of system components (infrastructure, data and software) to manage capacity demand and to enable additional capacity.
A1.2 Protections, backups and recovery infrastructure
The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains and monitors environmental protections (such as power and cooling), software, data backup processes and recovery infrastructure.
A1.3 Recovery testing
The entity tests recovery plan procedures supporting system recovery to meet its objectives.
What evidence shows availability
The examination looks at evidence that the controls are designed and in place and, in a type 2 report, that they operated over the period examined. For Availability, records like these show it:
- Capacity: what you monitor, the thresholds that trigger action and the record of each capacity review.
- Backups: what is backed up, how often according to your policy, and restore tests that show whether the data can be recovered.
- Recovery: the recovery plan for each service, with its recovery time objective (RTO) and its recovery point objective (RPO).
- Testing: a dated record of each recovery test, with its scope, conditions, result and corrective actions. Your engineering team or your provider runs the technical tests, and these records are part of what the CPA firm examines.
Where to start
The first step is agreeing with your customer what the report needs to cover. From there:
- Ask your customer whether it expects the Availability category and a type 1 or a type 2 report.
- List the services in scope and agree on the recovery objectives of each one.
- Gather the evidence you already have against A1.1 to A1.3 and note what is missing.
- Run a recovery test, document it and close what it shows; for a type 2 report, plan it inside the period the CPA firm will examine.
How we help
Gradiente prepares your company and its evidence for the Availability criteria: where your evidence stands against A1.1 to A1.3, the recovery test plan and the answers to your customers' questionnaires. The SOC 2 report is issued by the CPA firm after its examination.
Sources
These are the official sources for this guide, checked as of its update date. When a standard is sold by its publisher, we cite it by number and clause.
Let's talk about your next step.
In 30 minutes we review where you stand and suggest where to start.