What is SOC 2?

An independent audit report on a service organization's controls, covering security, availability and related trust criteria over a defined period.

An admin approves every new account by hand. Nothing is created until then. We reply by email; no newsletter, no sequence.

app.salescrew.io/inbox
The unified reply inbox with classified threads

SOC 2SOC 2 is an audit report, issued by an independent CPA firm, on a service organisation's controls for security, availability, processing integrity, confidentiality and privacy over a period. It is evidence about the vendor's controls, not a certification of the product.

Why it matters

SOC 2 is a report, not a badge. An outside CPA firm examines a service vendor's controls against a defined set of trust service criteria. Those can include security, availability, processing integrity, confidentiality and privacy. The firm issues a report describing what it found over a specific period. It is evidence about how well the controls were designed. In a Type II report, it also covers whether they operated effectively over that period. It is not a one-time stamp of approval that applies forever afterward.

The distinction that matters most for anyone judging a vendor is between the company and the product. A SOC 2 report speaks to the company's controls. Access management, change management, incident response, monitoring. It does not say a specific product is flawless or bug-free. A website that states "SOC 2 compliant" is making a claim that cannot be checked from that sentence alone. The report itself specifies which trust criteria were in scope, which systems were covered, and the exact period examined. Any of those can be narrower than the sentence on the website implies.

How a SOC 2 report comes about

  1. 1

    Trust criteria are scoped

    The company defines which criteria, security, availability, and others, the audit will cover.

  2. 2

    Controls are designed and documented

    Policies and technical controls for those criteria are put in place.

  3. 3

    An outside CPA firm examines them

    The firm checks whether the controls are designed well.

  4. 4

    Operation is tested over a period

    For a Type II report, the firm checks whether controls operated effectively over that time.

  5. 5

    A report is issued

    The findings, scope and period are documented in the final report.

The mistake to watch for

Reading "SOC 2 compliant" on a website as proof. Ask for the report and the period it covers. This is not legal advice.

Questions

How is SOC 2 different from ISO 27001?
SOC 2 is an audit report against trust service criteria, common in the US and issued by a CPA firm. ISO 27001 is an international certification against a formal information security management standard. It is issued by an approved certification body, with a different scope and process.
Does SOC 2 certify a specific product?
No. It reports on the company's controls, such as access management and incident response, over a defined period. It does not say any single product is free of defects.
What should someone ask for beyond the claim of SOC 2 compliance?
The actual report. It states which trust criteria were in scope, which systems were covered, and the specific period examined. A general claim on a website can be narrower than it sounds.