Observation window
The period a Type 2 examination covers to test whether controls operated effectively—not only whether they were designed. Related guide →
Sources: SOC 2 — SOC for Service Organizations: Trust Services Criteria
Reference
TL;DR. Canonical short definitions for observation window, Type 1/Type 2, TSC, questionnaires, and related founder terms. Educational only.
The period a Type 2 examination covers to test whether controls operated effectively—not only whether they were designed. Related guide →
A point-in-time examination of the design of controls relevant to selected Trust Services Criteria. Related guide →
An examination of design and operating effectiveness of controls over an observation window. Related guide →
AICPA criteria used in SOC 2 examinations: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Related guide →
The Security category of the Trust Services Criteria—often the scope of a first SOC 2 report. Related guide →
The contract that locks examination scope, period, fees, and responsibilities before fieldwork. Related guide →
The curated set of policies, tickets, screenshots, and logs that show controls existed and operated for the examiner. Related guide →
Cloud Security Alliance Consensus Assessments Initiative Questionnaire—yes/no questions mapped to the Cloud Controls Matrix. Related guide →
A streamlined CAIQ/CCM path oriented to SMEs and startups (see CSA STAR materials). Related guide →
Shared Assessments Standardized Information Gathering Lite template—commonly used for lower-risk or preliminary vendor questionnaires. Related guide →
The named person accountable for operating a control and producing its evidence on cadence. Related guide →
Beginning a SOC 2 program when a named deal, RFP, or recurring questionnaire makes the report load-bearing—not before. Related guide →