SOC 2
SOC 2 (Service Organization Control 2) is an attestation framework from the American Institute of CPAs that reports how a service organization handles customer data against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
A SOC 2 Type I report describes controls at a single point in time. A SOC 2 Type II report — the one enterprises usually ask for — covers an observation window of six to twelve months and demonstrates that the controls actually operated. Auditors issue the report; it is not a certification with a pass mark, but an independent opinion.
For cloud buyers, a current SOC 2 Type II is the baseline evidence of operational maturity. Ask for the report itself or a bridge letter if the observation window has partially lapsed, and check the criteria covered — security is mandatory, but availability and confidentiality are optional and matter most for production workloads.
Edits go through a quick editor review.
Comments (0)
No comments yet. Start the discussion below.
Leave a comment
Sign in to comment