SOC 2
An independent auditor's report on a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, under the AICPA's Trust Services Criteria.
A Type I report covers the design of the controls at a point in time; a Type II report also tests how they operated over a review period, often six to twelve months. Reports are restricted in use and usually shared under a non-disclosure agreement. Security is always in scope and the other criteria are optional, so it is worth checking which ones a vendor’s report covers, and which of its own vendors it carves out.
Source: AICPA Trust Services Criteria ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.