What it means
SOC 2 is a report rather than a certificate. Enterprise customers typically ask for a Type 1 point-in-time report first and a Type 2 report covering a period of operation as the service matures.
Applies to
- Cloud services and IoT platforms serving business customers
- Mobile backend and data processing environments
- Vendors in enterprise procurement processes
What it does not cover
- Device firmware security
- Consumer privacy law compliance
- A public certification mark
Verification checklist
- Choose the relevant trust services criteria
- Document policies and control evidence
- Complete a readiness assessment before the audit
- Publish the report under NDA to customers