Skip to main content
Back to Blog
May 4, 2026 by Arthur Mayoux GDPR & conformitate

Can you put a logoSOC2 on your website?

Most companies that use the AICPASOC logo have never registered for it.

Open ten trusted centres. Count the AICPASOC logos.

Now ask yourself how many of these companies registered with AICPA before marking the brand on their website.

The honest answer: probably very few.

There is a quiet assumption that goes through the GRC industry that getting a reportSOC2 comes with a free step to use the logo. No. The report is one thing.

What AICPA Terms Really Require

Three rules, none of them optional:

  1. You have to register. Official registration at AICPA. Acceptance of their terms and conditions. No check box in your Trust Center provider’s UI.
  2. No qualified opinions. If your SOC2 report returned with a modified opinion, the logo is out of the table.
  3. The logo expires. If you have not received a new SOC2 report within 12 months of the last report, download it.

Most service organizations know that there is a rule. Many of them ignore it anyway, because no one has knocked on the door.

What Changed on April 22

Previously, there were two logos: one for CPA firms taking the exams, one for service organizations who received aSOC1,SOC2 orSOC3.

Now there are three:

Logo Who can use it
SOC Logo for CPAs Licensed CPAs (or CPA firms) taking the examsSOC1,SOC2 orSOC3
AICPA SOC for Service Organizations Logo Any service body with at least one SOC1, SOC2 or SOC3 report from a licensed CPA (or non-US equivalent)
AICPA SOC 2 Logo for Service Organizations Specific services with a ratioSOC2 - a new specific brandSOC2 with "SOC2" ripe in design

If you have a SOC2 report, you can use any of the two services organization logos.

The new registration form is the real signal

The interesting part is not the third logo. is what AICPA now asks when you sign up.

The new form requires:

  • Name of the CPA who signed yourSOCreport
  • That CPA’s license number
  • Data raportului

The AICPA did not say what they would do with these data.The most likely answer: check it out.

Until now, the logo program of SOC has been a soft trademark with soft application. Collecting CPA license numbers at registration turns it into something that AICPA can actually audit.

New CPA Conditions Do a Real Job

Buried in the new logoSOCfor CPA terms and conditions this is:

“You further acknowledge that the Services and related reports carrying the Logo have been carried out in accordance with the relevant AICPA certification standards and other professional standards ... Therefore, you agree that any services or reports you provide under the CPA Logo will be of a quality level proportionate to that of the goods and services provided by AICPA before using the CPA Logo.”

Translation: If you are a CPA using the logo, you contractually certify that your work meets the AICPA quality standards.

Things that AICPA should still solve

Most CPA firms do not put the CPA logo on the reports they issue.

That’s backwards.

If the AICPA really wants to use logos as a quality assurance mechanism, a requirement for CPAs to display the logoSOCfor CPAs on each reportSOCs that issue it. This is the document that the customer reads. This is the artefact that is handed over to the buyer’s security team. Anchor the brand in the report itself, not just the marketing guarantee.

What to do this week

If you have a SOC2 report and display the AICPA logo:

  1. Confirm you’re registered. If you are not, register now.The new form is the only way to follow.
  2. Check your opinion. Cut the logo until you have a clean report.
  3. Check the date. More than 12 months from the last report? Take the logo down to the next.
  4. Pick the right logo. The new specific brand SOC2 is available if your report is SOC2.
  5. Audit your Trust Center. If the logo got there automatically, find out who put it there and what authority.

The logoSOC is not a participation trophy. It is a trademark with attached terms.

Do you want to display the official SOC logo? AICPA CIMA resource library (You must first create a free account.)


Scris de Arthur Mayoux
Arthur Mayoux write about operations, compliance programs and scaling security processes.
Portret Arthur Mayoux
ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert