Security and privacy

SOC 2 trust services report

An independent attestation report on controls covering security and, optionally, availability, processing integrity, confidentiality and privacy.

CodeSOC 2
RegionUnited States, used globally
TypeVoluntary, contractual
Issued byLicensed CPA firms
Last verified2026-10-10
Quick answerCertification · last verified 2026-10-10

An independent attestation report on controls covering security and, optionally, availability, processing integrity, confidentiality and privacy. Status: Voluntary, contractual. Issued or recognised by Licensed CPA firms.

CodeSOC 2
RegionUnited States, used globally
TypeVoluntary, contractual
Issued byLicensed CPA firms
GroupSecurity and privacy
Last verified2026-10-10
How to cite this pageIoT Atlas. "SOC 2 trust services report". https://hi-spark.net/certification/soc-2.html Last verified 2026-10-10.

What it means

SOC 2 is a report rather than a certificate. Enterprise customers typically ask for a Type 1 point-in-time report first and a Type 2 report covering a period of operation as the service matures.

Applies to

  • Cloud services and IoT platforms serving business customers
  • Mobile backend and data processing environments
  • Vendors in enterprise procurement processes

What it does not cover

  • Device firmware security
  • Consumer privacy law compliance
  • A public certification mark

Verification checklist

  • Choose the relevant trust services criteria
  • Document policies and control evidence
  • Complete a readiness assessment before the audit
  • Publish the report under NDA to customers