Issue 001 · Spring 2026Toronto · Global
Service Organization Control 2

SOC 2.

A security framework developed by the AICPA that defines how service organizations should handle customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Most enterprise buyers require vendors to be SOC 2 compliant.

§ Practitioner’s note

SOC 2 is the de-facto enterprise procurement gate in North America. If you sell SaaS to mid-market or larger buyers, the security questionnaire will eventually become "send us your SOC 2 report." The framework was developed by the AICPA (American Institute of Certified Public Accountants) and audits are issued by licensed CPA firms. Reports cover any of five Trust Services Criteria — Security is mandatory; Availability, Processing Integrity, Confidentiality, and Privacy are optional but increasingly common. SOC 2 is voluntary in the sense that no law requires it, but commercially you do not get to opt out once a buyer asks.

Need help with SOC 2?

We do this work every day for Canadian teams. Book a free 30-minute consultation.

Talk to MALTO Cyber →