A SOC 2 is an attestation, which means the company speaks first and the auditor evaluates what was said. Management asserts three things: the system description is fairly presented, controls were suitably designed to meet the selected Trust Services Criteria, and — in a Type 2 — they operated effectively across the period. The opinion in Section I is the auditor agreeing, or declining to agree, with exactly those claims, which is why the two documents mirror each other’s language. Skip the assertion and there is no audit; the opinion would have nothing to attach to.
Because it is a formal statement over the company’s signature, the assertion is drafted with care and signed by an executive who can stand behind it — typically the CEO, CTO, or head of security. It gets finalized near the end of fieldwork, once the evidence supports every word, and auditors push back on language that overreaches. For the complete anatomy — each of the three claims unpacked, who signs, common wording, and a realistic skeleton you can adapt — see our full guide to the SOC 2 management assertion.