Evaluating controls: The core responsibility of a SOC 2 Type 2 assessor is to evaluate an organization's internal controls against the relevant AICPA Trust Services Criteria (TSC). These criteria include:
Security: Protection against unauthorized access, disclosure, and damage.
Availability: Ensuring systems are available for operation and use.
Processing Integrity: Ensuring accurate, complete, and timely data processing.