Compliance framework

What is SOC 2?

SOC 2 is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates how service organizations manage customer data. It covers five Trust Service Criteria: security, availability, processing integrity, confidentiality, and privacy.

A SOC 2 report is prepared by an independent CPA firm. It can be a Type I report, which evaluates the design of controls at a point in time, or a Type II report, which additionally evaluates operating effectiveness over a period — typically six to twelve months. Most enterprise procurement teams require a SOC 2 Type II as a baseline vendor qualification.

Which vendors hold SOC 2?

Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.

Common questions about SOC 2

Which vendors hold SOC 2 certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current SOC 2 certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does SOC 2 certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's SOC 2 report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.

Related frameworks

SOC 2 TYPE 1SOC 2 TYPE 2ISO 27001