SOC 2 report
SOC 2 · An audit report, especially common in the United States, in which independent auditors assess a service organisation's controls for security, availability, processing integrity, confidentiality and privacy.
- 01
Why it matters
US customers often ask software service companies for a SOC 2 report. A Type I report shows that controls were designed correctly at a given date; a Type II report shows they actually operated over a period. That is why Type II is considered stronger evidence.
- 02
Example
A SaaS company that wants to win a US client starts with a Type I report, then obtains a Type II report after a six-month observation period and answers security questions in sales talks with it.
- 03
Common mistake
Thinking of SOC 2 as a certificate. The report is an auditor's opinion and its scope matters; check whether the service the customer uses is within that scope.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.