[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-soc-2::en":3,"gloss-cluster-soc-2::en":20,"gloss-next-soc-2::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"soc-2","saas","SOC 2","SOC 2 (System and Organization Controls 2) is a security and compliance audit framework, defined by the American Institute of CPAs (AICPA), under which an independent auditor examines and reports on a company's internal controls across some or all of five \"Trust Services Criteria\": Security (mandatory), Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a certification with a fixed checklist, SOC 2 is an audited attestation — the auditor verifies that the controls a company claims to have (access controls, encryption practices, incident-response procedures, vendor-management processes, employee offboarding procedures, etc.) are actually in place and, for a Type II report, that they operated effectively over a sustained observation period (typically 6–12 months), as opposed to a Type I report, which only attests controls existed and were suitably designed at a single point in time. SOC 2 has become a near-universal procurement gate for B2B SaaS selling into mid-market and enterprise customers — a prospective enterprise buyer's security\u002Fprocurement team will routinely refuse to even begin contract negotiations without a current SOC 2 Type II report, making it one of the highest-leverage, non-negotiable investments an early-stage B2B SaaS company makes as it moves upmarket. The process typically starts with tooling like Vanta, Drata, or Secureframe, which automate evidence collection (screenshotting access-control configs, monitoring for unencrypted data stores, tracking employee security training completion) and continuously monitor control compliance year-round, feeding directly into the eventual audit. Concrete worked example: a 15-person SaaS startup closing its first enterprise deal is asked by the buyer's security team for a SOC 2 report as a contract prerequisite. The startup enrolls in Vanta, which surfaces gaps against the required controls — no formal employee offboarding checklist, database encryption-at-rest not yet enabled, no documented incident-response plan — the team remediates each gap over 6 weeks, then engages an accredited auditor for a Type I report (fast, point-in-time) to unblock the immediate deal, while committing to a Type II observation period over the following 9 months for future enterprise deals that specifically require it. It's worth noting SOC 2 is a US\u002FAICPA framework specifically — companies selling internationally often need to pursue complementary certifications like ISO 27001 (the broadly recognized international information-security standard) alongside SOC 2, since some enterprise buyers and government procurement processes outside North America specifically require ISO 27001 rather than accepting SOC 2 as a substitute. A SOC 2 report itself is confidential, shared under NDA with prospective customers rather than published publicly, which is why SaaS vendors typically gate access to their report behind a request form or a trust-center page (via Vanta Trust or Drata Trust) that also surfaces subprocessor lists and other compliance artifacts a security-review process commonly asks for.","SOC 2 is a widely-required security compliance audit and report verifying a SaaS vendor's controls around data security, availability, and confidentiality.",null,[11,14,17],{"slug":12,"name":13},"gdpr","GDPR (General Data Protection Regulation)",{"slug":15,"name":16},"sla","Service-Level Agreement (SLA)",{"slug":18,"name":19},"sso","Single Sign-On (SSO)",[21,25,29,32,35,38,41,45,48,51,54,57],{"slug":22,"category":5,"name":23,"updated_at":24},"activation","Activation","2026-08-24T02:46:36+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"aha-moment","Aha Moment","2026-08-24T02:46:37+00:00",{"slug":30,"category":5,"name":31,"updated_at":28},"annual-contract-value","Annual Contract Value (ACV)",{"slug":33,"category":5,"name":34,"updated_at":24},"api-first","API-First",{"slug":36,"category":5,"name":37,"updated_at":24},"arpa","Average Revenue Per Account (ARPA)",{"slug":39,"category":5,"name":40,"updated_at":24},"arr","Annual Recurring Revenue (ARR)",{"slug":42,"category":5,"name":43,"updated_at":44},"auto-renewal-clause","Auto-Renewal Clause","2026-08-24T02:46:38+00:00",{"slug":46,"category":5,"name":47,"updated_at":44},"build-vs-buy","Build vs. Buy",{"slug":49,"category":5,"name":50,"updated_at":28},"burn-multiple","Burn Multiple",{"slug":52,"category":5,"name":53,"updated_at":44},"burn-rate","Burn Rate",{"slug":55,"category":5,"name":56,"updated_at":24},"cac","Customer Acquisition Cost (CAC)",{"slug":58,"category":5,"name":59,"updated_at":24},"cdn","Content Delivery Network (CDN)"]