Glossary SOC 2
SOC 2
Also known as:
socs, soc2, service-organization-controlTechComplianceVendors
Definition
A third-party attestation (AICPA) that a service provider's controls over security, availability, processing integrity, confidentiality and privacy are designed — Type I — and operating over a period — Type II — as described
Not a certification of the software but of the organization running it; it is what a vendor questionnaire is really asking for. It matters here when choosing processors — analytics, email, hosting, database — whose report can be requested, so the site's own privacy claims rest on more than the vendor's marketing page.
The audit a vendor hands you instead of an argument. Type II is the one worth asking for: it says the controls held for months, not that they existed on the day of the visit.