Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Compliance

SOC 2

SOC 2 is an attestation report, defined by the AICPA, in which an independent auditor gives an opinion on the controls a service organization operates to meet the Trust Services Criteria: security (always in scope), and optionally availability, processing integrity, confidentiality and privacy. A Type I report describes the design of the controls at a point in time; a Type II report tests that they operated effectively over a period, typically six to twelve months. It is a report to be read, not a certificate to be displayed.

Read the report, not the badge

A SOC 2 report carries the scope (which services, which criteria), the system description, the controls the provider chose, the auditor’s tests and their results, including the exceptions found. A “SOC 2 compliant” logo tells a buyer none of this. The useful questions are: which criteria were in scope, was it Type II and over what period, what exceptions were noted, and which of the provider’s subservice organizations were carved out and therefore not covered.

SOC 2 and ISO 27001, side by side

ISO 27001 certifies a management system against a fixed control catalog; SOC 2 attests the effectiveness of controls the provider defined itself against principles. Many SaaS vendors hold both, and the control set largely overlaps: access management, change management, incident response, vendor management, logging. A single mapped control set with evidence collected once serves both, which is the practical reason continuous compliance programs start by mapping rather than by choosing.

In third-party risk

For a buyer, a supplier’s SOC 2 Type II is one of the strongest pieces of evidence available, and one of the most misread. Used well, it answers specific control questions in an assessment without a questionnaire, provided the scope covers the service actually bought and the period is recent. Used badly, it replaces the assessment entirely. The report should feed a supplier’s evidence base and its grade, next to the buyer’s own questions and the external signals about that supplier.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.