Compliance frameworks

SOC 2 (System and Organization Controls 2)

SOC 2 is an AICPA attestation report on a service organization's controls relevant to the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. SOC stands for System and Organization Controls. A Type 2 report covers how the controls operated over a period of time, typically 6 to 12 months, and is widely requested in B2B software procurement.