SOC 2

SOC 2 (System and Organization Controls 2) is a security and compliance audit framework, defined by the American Institute of CPAs (AICPA), under which an independent auditor examines and reports on a company's internal controls across some or all of five "Trust Services Criteria": Security (mandatory), Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a certification with a fixed checklist, SOC 2 is an audited attestation — the auditor verifies that the controls a company claims to have (access controls, encryption practices, incident-response procedures, vendor-management processes, employee offboarding procedures, etc.) are actually in place and, for a Type II report, that they operated effectively over a sustained observation period (typically 6–12 months), as opposed to a Type I report, which only attests controls existed and were suitably designed at a single point in time. SOC 2 has become a near-universal procurement gate for B2B SaaS selling into mid-market and enterprise customers — a prospective enterprise buyer's security/procurement team will routinely refuse to even begin contract negotiations without a current SOC 2 Type II report, making it one of the highest-leverage, non-negotiable investments an early-stage B2B SaaS company makes as it moves upmarket. The process typically starts with tooling like Vanta, Drata, or Secureframe, which automate evidence collection (screenshotting access-control configs, monitoring for unencrypted data stores, tracking employee security training completion) and continuously monitor control compliance year-round, feeding directly into the eventual audit. Concrete worked example: a 15-person SaaS startup closing its first enterprise deal is asked by the buyer's security team for a SOC 2 report as a contract prerequisite. The startup enrolls in Vanta, which surfaces gaps against the required controls — no formal employee offboarding checklist, database encryption-at-rest not yet enabled, no documented incident-response plan — the team remediates each gap over 6 weeks, then engages an accredited auditor for a Type I report (fast, point-in-time) to unblock the immediate deal, while committing to a Type II observation period over the following 9 months for future enterprise deals that specifically require it. It's worth noting SOC 2 is a US/AICPA framework specifically — companies selling internationally often need to pursue complementary certifications like ISO 27001 (the broadly recognized international information-security standard) alongside SOC 2, since some enterprise buyers and government procurement processes outside North America specifically require ISO 27001 rather than accepting SOC 2 as a substitute. A SOC 2 report itself is confidential, shared under NDA with prospective customers rather than published publicly, which is why SaaS vendors typically gate access to their report behind a request form or a trust-center page (via Vanta Trust or Drata Trust) that also surfaces subprocessor lists and other compliance artifacts a security-review process commonly asks for.

Related terms

More SaaS & Growth terms