SOC 2
System and Organization Controls 2
Audit framework for service orgs covering security, availability, confidentiality.
Security & Compliance
When you'd see it: Vendor security reviews and enterprise sales. Buyers ask for a SOC 2 report before trusting a SaaS vendor with their data.
Why it matters: SOC 2 is an independent audit of how a service organization handles security, availability, and privacy, and the report is often the ticket to selling into larger customers. Type II, which tests controls over months, is the one enterprises expect.
Common mistakes: Confusing SOC 2 Type I (controls exist at a point in time) with Type II (controls worked over months). Enterprises generally want Type II.
Study this in BizTech Primer →