SOC 2 — System and Organization Controls 2

Definition

An audit framework developed by the AICPA for service providers, focusing on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy.

Context & Usage

SOC 2 is critical for SaaS vendors, cloud providers, and managed service providers selling to enterprise customers. Two report types: Type I (point-in-time controls existence) and Type II (controls effectiveness over 6-12 months). Most enterprise software vendors maintain SOC 2 Type II certification.

Examples

  • AWS, Microsoft Azure, Google Cloud all have SOC 2 Type II
  • Salesforce, ServiceNow SOC 2 reports

Looking for SOC 2 hardware?

Pro Disk Network stocks enterprise IT hardware spanning every category. Email sales@prodisknetwork.com with your requirements for a quote.

Part of

B2B Procurement & Industry Solutions Hub

View all 248 pages →

Net 30 terms, RFQ workflow, federal / K-12 / healthcare / MSP procurement — for buyers spending $50K+ annually.