Skip to content
Illuminated WesternTechSystems signage at dusk

Compliance · SOC 2

SOC 2 is not a certification, and the distinction matters at disposal

An attestation on controls an organization defined and scoped itself is a different thing from a certification against an external standard. Knowing which you are holding changes what you can rely on it for — and what your own auditor will accept.

In one paragraph

The short version

Criterion CC6.5 is the one that matters for disposal: protections over a physical asset may be discontinued only after the ability to read or recover data from it has been diminished. It sits in the Common Criteria, so it applies to every SOC 2 engagement.

A vendor's SOC 2 report is evidence about that vendor. It does not transfer to you, it does not discharge your obligations under HIPAA, GLBA or the FACTA Disposal Rule, and it is only worth anything if you read it — the scope, the period, the exceptions and the controls it assumes you are operating.

1 · The obligation

What the rule actually says

Cited to the AICPA Trust Services Criteria. Quoted rather than paraphrased, because the paraphrases in circulation are where most of the confusion starts.

AICPA Trust Services Criteria — CC6.5

The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.

This is the criterion actually on point for asset disposal, and it sits in the Common Criteria — meaning it is in scope for every SOC 2 engagement, because Security is mandatory. Vendors more often cite the Confidentiality category, which is optional and which many reports do not elect at all.

https://www.aicpa-cima.com/

Confidentiality criterion C1.2

C1.2 is the confidentiality-category disposal criterion and it exists, but we are not quoting it here because we could not retrieve its wording from the AICPA's own document — the Trust Services Criteria PDF is behind an account wall. Rather than reproduce a version circulating on compliance blogs, we point you at CC6.5, which is verified, applies to every SOC 2 report rather than only those electing Confidentiality, and is the better citation for disposal anyway.

https://www.aicpa-cima.com/

2 · The misreading

What the rule does not say

This is the section most vendor pages omit, and it is the one that decides whether the rest of the page can be trusted.

  • SOC 2 is not a certification. It is an attestation engagement: a CPA firm reports an opinion on a service organization's own description of its system and on the suitability and operating effectiveness of its own controls. The correct phrasing is that an organization has completed a SOC 2 Type II examination, not that it is SOC 2 certified.

  • It is not issued, recognized or accredited by any government body. AICPA is a private professional association.

  • The scope is chosen by the organization being examined. Which criteria are elected, which systems are in scope and which controls are tested are all decisions of the service organization. Two SOC 2 reports are not comparable without reading both.

  • A vendor's SOC 2 report says nothing about your compliance. It is evidence about that vendor's control environment. It does not discharge your obligations under 45 CFR 164.308(b), 16 CFR 314.4(f) or 16 CFR 682.3.

  • A logo is not a report. The only version of this that has any evidential value is the one where you read the report — checking that disposal controls are genuinely in scope, that the period covered is current, and that there is no qualified opinion or relevant exception.

3 · The evidence

What an auditor actually asks for

The report itself, not the badge

Type II rather than Type I where it matters, because Type I is a point-in-time opinion on design and says nothing about whether the control operated.

Whether disposal controls are in scope

CC6.5 is in the Common Criteria so it should be — but the systems and processes covered by the description are the organization's own choice, and disposal is not always inside them.

The period covered, and whether it is current

A report covering a period that ended fourteen months ago is a historical document.

Exceptions and any qualification

The interesting part of a SOC 2 report is rarely the opinion paragraph. It is the testing exceptions and management's responses.

Complementary user entity controls

Every report lists the controls it assumes you are operating. Those are your obligations, spelled out by your vendor's auditor, and almost nobody reads them.

4 · Our part

What our documentation provides against it

Artefact What it answers
Per-serial erasure certificate Direct evidence for the CC6.5 question — that the ability to recover data was removed before protections over the asset were discontinued.
Chain-of-custody record The interval between an asset leaving your protection and being sanitized, which is precisely the window CC6.5 is written about.
Intake reconciliation report What arrived against what was manifested, so an asset cannot quietly disappear between your register and our floor.
Method statement What was applied to which media class, so your auditor can assess whether recoverability was genuinely diminished rather than assumed.
R2v3 and RIOS certification Independent third-party certification of the management system. It is not a SOC 2 report and we will not present it as one, but it is evidence your auditor can weigh.
Facility and records access Walkthrough and records review by appointment — useful when your auditor wants to test the vendor control rather than accept a document.

5 · Your part

What remains your obligation

No vendor can discharge these for you. Any vendor implying otherwise is selling you a risk you will still be holding.

  • Reading the report you were given, including the exceptions and the complementary user entity controls.
  • Operating the controls that report assumes you operate. They are listed in it, and they are yours.
  • Deciding whether disposal is in scope for your own SOC 2, and evidencing CC6.5 for your own assets.
  • Keeping your asset register reconcilable to the disposal evidence. An auditor tests the link between the two, not either one alone.
  • Not treating a vendor badge as a control. It is an input to your assessment, and an auditor who is paying attention will say so.

FAQ

SOC 2 and disposal questions

Is a SOC 2 certified disposal vendor better than an R2 certified one?
The comparison does not quite work, and it is worth understanding why. SOC 2 is not a certification at all — it is a CPA firm's attestation on controls the organization itself defined and scoped. R2v3 is a certification against a published standard, audited by a body accredited for that purpose. They answer different questions: SOC 2 asks whether an organization's own stated controls operated, R2v3 asks whether it meets an external standard for responsible recycling and data security. Neither confers compliance on you.
Which criterion covers asset disposal?
CC6.5, in the Common Criteria: protections over physical assets are discontinued only after the ability to read or recover data from them has been diminished. Because Security is mandatory in every SOC 2 engagement, CC6.5 applies to every SOC 2 report. The Confidentiality category has its own disposal criterion, but Confidentiality is optional and many reports do not elect it.
Why does this page not quote the Confidentiality criterion?
Because we could not verify its wording at the source. The AICPA's Trust Services Criteria document is behind an account wall, and the copies we could reach truncated before that criterion. We would rather cite the criterion we verified than reproduce wording we found on a compliance vendor's blog — which is, incidentally, the same standard of evidence this whole section is arguing you should apply to us.
Our auditor asked for our disposal vendor's SOC 2 report. What if they do not have one?
Then the question becomes what other evidence supports the control. Third-party certification of the management system, a documented chain of custody, serial-level destruction records and the ability to inspect the facility are all evidence an auditor can weigh. What does not work is having none of those and offering a logo instead.

Send us your auditor's request.

Tell us what has been asked for and we will tell you which of it we can evidence — and which of it is yours to produce.