SOC 2.
A security framework developed by the AICPA that defines how service organizations should handle customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Most enterprise buyers require vendors to be SOC 2 compliant.
SOC 2 is the de-facto enterprise procurement gate in North America. If you sell SaaS to mid-market or larger buyers, the security questionnaire will eventually become "send us your SOC 2 report." The framework was developed by the AICPA (American Institute of Certified Public Accountants) and audits are issued by licensed CPA firms. Reports cover any of five Trust Services Criteria — Security is mandatory; Availability, Processing Integrity, Confidentiality, and Privacy are optional but increasingly common. SOC 2 is voluntary in the sense that no law requires it, but commercially you do not get to opt out once a buyer asks.
Connected concepts.
SOC 2 Type I vs Type II
Point-in-time vs. ongoing assessmentType I assesses security controls at a single moment — a snapshot. Type II evaluates controls over a period (typically 3–12 months) to verify they operate consistently. Most companies start with Type I and progress to Type II.
ISO 27001:2022
International information security standardThe 2022 revision of ISO’s information security management system (ISMS) standard. Widely used outside North America and increasingly required by European and Asian enterprise buyers. Includes 93 controls across 4 themes.
Need help with SOC 2?
We do this work every day for Canadian teams. Book a free 30-minute consultation.
Talk to MALTO Cyber →