SOC 2
SOC 2 is an audit report in which an independent accounting firm confirms that a software provider properly protects its customers' data. For companies that sell software to other companies, such a report is often the ticket to sales conversations.
When a company uses another company’s software, it also hands over data: customer lists, contracts, payroll data. The obvious question then is: how secure is that data really over there? The provider could simply claim that everything is fine. SOC 2 is the way to have that verified. An independent audit firm looks at how the provider handles data and writes a report about it. The name comes from the US professional association of accountants, which set the rules for it.
The ticket into enterprise sales
For software companies that sell to other companies, SOC 2 is barely negotiable anymore. Large customers such as banks, insurers, or corporations ask for the report early in the sales conversation. Without it, the conversation often ends before it even gets to price. The report replaces trust with something verifiable.
The reason for this is the chain reaction that occurs with security incidents. If a service provider gets hacked, hundreds of its customers are often affected at once. A corporation’s procurement department, however, cannot possibly vet every supplier itself. So it demands a report that an auditor has already produced. A SOC 2 report thus becomes a document you can show to many customers, instead of filling out a hundred questionnaires individually.
For young companies, this is a noticeable cost item. Audit, consulting, and tools can quickly add up to a five-figure amount per year. Still, many start-ups get the report early, because it’s what makes larger customers possible in the first place. In financial news, SOC 2 therefore often comes up when the question is whether a provider is ready for enterprise customers.
What the auditors look at
SOC 2 doesn’t test against a rigid checklist. There are five subject areas, called Trust Services Criteria in the original English. Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is always included; the company chooses the other four based on its business. A video conferencing provider is more likely to have Availability audited, while an accounting provider is more likely to focus on correct data processing.
Within these areas, the company itself describes which safeguards it uses. Typical ones include: passwords with a second factor, encrypted hard drives, logged access, and regulated granting and revoking of permissions. The auditor then assesses whether these measures are sensible and whether they were actually applied. To do so, they require evidence, such as log files or screenshots from the systems.
The distinction between two report types matters. A Type I report only examines a single point in time: do the measures exist today? A Type II report observes a period, usually three to twelve months, and checks whether they were consistently followed. Type II is considered the serious proof, Type I more of an intermediate step.
A report, not a seal on the wall
In everyday life, SOC 2 is mostly encountered on the websites of cloud providers, meaning companies that deliver software over the internet. There’s usually a brief mention on a page about security or trust. However, you rarely get the full report available for free download. It contains details about internal technology and is therefore only issued after signing a non-disclosure agreement.
A common misconception: that SOC 2 is a certificate you either pass or fail. In fact, it is an auditor’s opinion in written form. They can note deviations, so-called exceptions, and the report is still valid. So anyone reading it should not just check whether it exists, but pay attention to these notes.
SOC 2 should be distinguished from two related terms. ISO 27001 is an international standard with an actual certificate and is more widespread in Europe. The General Data Protection Regulation, on the other hand, is a law and applies regardless of whether one has been audited. A SOC 2 report replaces neither, it complements them. And because reports only cover a past period, providers generally have them redone every year.