Skip to content
The Internet Compass

Security

SOC 2

SOC 2 is an auditing framework assessing a service organisation's controls against trust services criteria (security, availability, processing integrity, confidentiality and privacy), resulting in an independent auditor's report.

Type I evaluates control design at a point in time; Type II evaluates operating effectiveness over a period, usually three to twelve months, and is what enterprise buyers actually want.

SOC 2 is an attestation about controls, not a certification of security. It tells a buyer that a company does what it says, not that what it says is sufficient.