Cybersecurity Glossary

SOC 2

An audit report on how a service provider handles security and related commitments.

What SOC 2 means

A SOC 2 report is produced by an accountancy firm against trust criteria such as security, availability and confidentiality. A Type I report assesses the design of controls at a point in time; a Type II assesses whether they operated effectively over a period, usually several months.

Why SOC 2 matters for small businesses and nonprofits

It is the report most commonly requested of technology suppliers in the United States. If you sell software or managed services to mid sized clients, expect to be asked for one, and expect Type II to be what they mean.

What to do about SOC 2

Three steps to deal with SOC 2

  • Confirm which type and which criteria your customers actually require
  • Allow for an observation window of several months before the report exists
  • Ask your own suppliers for theirs, since their controls become part of yours

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.