Risk Management - Standard
SOC 2
(System and Organization Controls 2)
An independent audit report on how well a service provider controls areas such as security and availability
What's it for?
Gives customers independent evidence about how well a service provider's security and related safeguards operate.
For example…
Security reviews an independent report before trusting a new supplier with data
A SaaS vendor provides customers with its SOC 2 Type II report so they can assess whether security controls operated effectively over the audited period
Think of it like…
An inspector's report on a warehouse's locks and processes over several months, not a one-day snapshot selfie