Compliance framework

What is SOC 2 Type II?

A SOC 2 Type II report evaluates both the design and the operating effectiveness of a service organization's controls over an audit period — typically six to twelve months. It is the gold standard for third-party security attestation in the SaaS industry.

The Type II audit tests that controls were consistently applied throughout the period, not just present on the audit date. Any exceptions found during the period are listed in the report's exception table. TrustVendor automatically extracts these exceptions and surfaces the ones relevant to your data classes.

Which vendors hold SOC 2 Type II?

Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.

Common questions about SOC 2 Type II

Which vendors hold SOC 2 Type II certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current SOC 2 Type II certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does SOC 2 Type II certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's SOC 2 Type II report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.

Related frameworks

SOC 2SOC 2 TYPE 1ISO 27001