On this page
- How do you download the official SOC 2 logo?
- Which official SOC 2 logo should you use?
- Is there an official AICPA SOC 2 Type 2 logo?
- How should you show that SOC 2 is in progress?
- Which SOC 2 badges are safe to use?
- What wording should accompany a SOC 2 badge?
- What should you confirm before publishing the logo?
The official SOC 2 logo is available through the AICPA’s SOC for Service Organizations registration and download page. On April 22, 2026, AICPA listed both a general SOC mark and a SOC 2-specific mark for eligible service organizations. Download the approved asset after registering and reading the current terms.
Official download: Get the current AICPA SOC logo files and guidelines.
We link to AICPA rather than mirror its files so you receive the current asset and accept the applicable terms.
How do you download the official SOC 2 logo?
Download the official SOC 2 logo directly from AICPA after signing in or creating a free account. The registration flow connects the asset to the organization and report that support its use.
- Open the AICPA logo resource. Use the SOC for Service Organizations registration and download page, not an image library or copied file.
- Sign in or register. AICPA labels the resource as free-account access. Complete the current registration information requested for your organization and report.
- Read the terms and choose the matching mark. Keep the approved file, registration record, and current guidelines with the person responsible for publishing the asset.
A transparent PNG, SVG, Figma component, or vector found elsewhere may be outdated or governed by different permissions. The file format alone does not establish that an asset is official or licensed for your use.
Which official SOC 2 logo should you use?
The AICPA public resource dated April 22, 2026 describes two service-organization marks:
- AICPA SOC for Service Organizations Logo for use by Service Organizations is the general mark for organizations that have received a SOC 1, SOC 2, or SOC 3 report from a licensed, independent CPA or a non-U.S. equivalent.
- AICPA SOC 2 Logo for use by Service Organizations is the SOC 2-specific mark for organizations that have received a SOC 2 report from a licensed, independent CPA or a non-U.S. equivalent.
Choose the mark that matches the report you received and the current AICPA terms. If the wording or available files change, follow the current AICPA page.
Is there an official AICPA SOC 2 Type 2 logo?
The April 2026 AICPA resource names a SOC 2 service-organization mark. It does not list a separate official AICPA mark for Type 1 or Type 2. A graphic labeled “SOC 2 Type II” may be an auditor, compliance-platform, or custom asset; it is not automatically an official AICPA logo.
Use your report type in nearby copy where it gives buyers useful context. For example: “We received a SOC 2 Type 2 report covering [system or service] for the period [dates].” Do not alter an official mark to add “Type 2,” and do not assume that a third-party Type II graphic carries AICPA permission.
How should you show that SOC 2 is in progress?
Use a dated, plain-text status statement while your SOC 2 work is underway. AICPA’s April 2026 public resource does not list an official “in progress” mark, so the wording should describe the stage you can verify.
Examples that keep the claim specific:
- “We are preparing for a SOC 2 examination.”
- “Our SOC 2 Type 2 examination is in progress; we expect the observation period to end in September 2026.”
- “We are working with an independent CPA firm on our SOC 2 readiness and examination process.”
Only publish dates, report type, and auditor involvement that your security or legal owner can confirm. Remove or update the statement when the underlying status changes.
Which SOC 2 badges are safe to use?
Use a SOC 2 badge only when its issuer gives your organization permission and the underlying status is current. The asset source determines which terms apply and what the badge can claim.
| What you have | What to use | What to check first |
|---|---|---|
| A SOC report and a current AICPA registration | The AICPA mark available through your registration | Current AICPA guidelines and the report that supports the claim |
| A platform or auditor-provided badge | The issuer’s badge, if its license permits your intended use | The issuer’s current terms; do not describe it as an AICPA asset |
| An audit or readiness effort in progress | Plain-text status copy | The stated scope, stage, and date with your internal owner |
| A PNG, JPG, SVG, or Figma asset from an image library or search result | Nothing until its source and permission are verified | Whether it is official, current, and licensed for your use |
What wording should accompany a SOC 2 badge?
A SOC 2 badge should sit beside a precise statement of the report type, system scope, audit period, and report-request path. The badge signals that a report exists; the accompanying copy tells a buyer what that report covers.
| Accurate status wording | Avoid |
|---|---|
| We received a SOC 2 Type 2 report | We are SOC 2 certified |
| Our SOC 2 report covers Security and Availability | We are fully certified secure |
| Our independent CPA issued an unqualified opinion | We passed every security standard |
SOC 2 is an attestation engagement, not a certification against a universal pass-or-fail standard. People often use “SOC 2 certified” as shorthand, but accurate SOC 2 terminology makes the public claim easier for auditors and security buyers to verify.
Place the mark where buyers evaluate security claims, such as a trust center, security page, enterprise plan page, or sales deck. Link to the report-request workflow or security contact rather than suggesting that the badge itself proves the scope. A guide to reviewing a SOC 2 audit report explains what the underlying document can answer.
What should you confirm before publishing the logo?
Check the current AICPA guidance first, then have the report owner confirm the specific public wording. The public AICPA page requires registrants to read and understand the guidelines before downloading and displaying a mark. Probo’s May 4, 2026 review of the new AICPA terms says a service organization must register, a report with a qualified or otherwise modified opinion is ineligible, and continued display requires a new report within 12 months.
Verify those points in the current AICPA terms you accept before publishing. The operative guideline PDFs are account-gated, so the public page is not a substitute.
Before a page, deck, or press release goes live, confirm:
- which report supports the statement;
- which AICPA mark or third-party badge you are licensed to use;
- who owns review when the report is renewed, qualified, or replaced; and
- where buyers can obtain the appropriate supporting material.
For the wider framework, report types, and audit process, use the SOC 2 compliance guide. For logo files and display terms, return to the official AICPA registration page.