SOC 2

Noun · Security & Infosec

Definitions

  1. A compliance framework developed by AICPA that evaluates an organization's controls for Security, Availability, Processing Integrity, Confidentiality, and Privacy. Type I assesses controls at a point in time; Type II assesses effectiveness over a period (usually 12 months). Required by most enterprise customers before they'll use a SaaS product.

    In plain English: A security audit that proves your company handles customer data safely, required by most enterprise buyers.

    Example: "We can't close the enterprise deal without SOC 2 Type II — they need proof that our security controls have been operating effectively for a year."

Related Terms