Theme comparison · soc-2-vs-ccpa
SOC 2 vs CCPA
SOC 2 vs CCPA and CPRA for SaaS: compare CPA assurance with California privacy law, security overlap, consumer rights, contracts, and sequencing.
Frameworks covered: SOC 2
Key differences
| Dimension | Approach A | Approach B |
|---|---|---|
| Nature | SOC 2 is a voluntary CPA attestation against AICPA Trust Services Criteria. | CCPA, as amended by CPRA, is California privacy law enforced by the CPPA, Attorney General, and in limited cases private actions. |
| Applicability | Driven by customer assurance needs; management selects the service boundary and applicable Trust Services Categories. | Applies to qualifying for-profit businesses meeting statutory thresholds and extends contract duties to service providers, contractors, and third parties. |
| Data definition | Controls protect information and systems described in the report, with categories selected by commitments and risks. | Personal information and sensitive personal information are broadly defined around California consumers and households, subject to exemptions. |
| Output | A Type I or Type II report contains a system description, tests, results, and CPA opinion. | Compliance produces notices, request handling, contracts, opt-out mechanisms, minimization, retention, and reasonable security—not an audit report. |
| Consumer control | Privacy criteria can cover notice, choice, access, and disposal when included, but security-only reports may not. | Consumers receive rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive-data uses, and non-discrimination. |
| Vendor terms | CC9.2 addresses risk management for vendors and business partners; subservice organizations are disclosed in the system description. | Service-provider and contractor agreements must restrict use, sharing, retention, and downstream handling under statutory definitions. |
| Security consequences | Control failures create report exceptions, customer concerns, and contractual exposure. | Failure to maintain reasonable security can drive enforcement and a private right of action for certain breaches. |
Control overlap
SOC 2 evidence can strengthen a CCPA/CPRA reasonable-security program but does not establish privacy-law compliance. Access controls such as /controls/soc-2/cc6-1, monitoring and incident controls in CC7, change management in CC8.1, and vendor oversight under CC9.2 support defensible safeguards. Asset inventories, deletion logs, incident records, and vendor reviews may be reused. CCPA-specific work remains: notices at collection, privacy disclosures, consumer-request verification and response, sale/share analysis, Global Privacy Control handling, sensitive-personal-information limits, retention rules, and service-provider/contractor language. A report scoped to production may omit marketing and advertising systems central to CCPA risk.
Sequencing advice
For a SaaS business subject to CCPA/CPRA, inventory California personal information across product, website, sales, support, HR, and advertising systems before setting the SOC 2 boundary. Implement request intake, identity verification, deletion and correction propagation, opt-out signals, retention, and contract classifications as legal operations. In parallel, build shared technical controls and begin the Type II observation period when they operate consistently. Use the SOC 2 report as customer assurance, not as the privacy compliance conclusion. Ensure marketing cookies and ad-tech recipients are reviewed even if excluded from the audited service, and keep CPPA/Attorney General interpretations under periodic legal review.