Definition
SOC 2 is an independent audit report attesting that a vendor's controls for security, availability, and confidentiality meet defined criteria.
A Type II report - covering a period of operation, not a single point in time - is the meaningful one. Read the exceptions section, not just the logo: that's where the auditor records what didn't pass.
Go deeperVendor due diligence checklistRelated terms
Benchside turns soc 2 into the exact questions, exclusions, and lock-in math for your specific vendor - your first project is free.