Data Rooms Providers Find a data room
VDR glossary · Compliance and privacy

What is SOC 2?

Definition

SOC 2: An attestation framework from the American Institute of CPAs in which an auditor reports on a service provider's controls for security and, optionally, availability, confidentiality, processing integrity and privacy.

How it works in a data room

A licensed CPA firm examines the provider’s controls against the trust services criteria. A Type I report looks at whether controls are well designed at one point in time; a Type II report tests whether they actually operated over a period, usually six to twelve months. The report is confidential and is normally shared under a nondisclosure agreement. Reading it means checking the period covered, the criteria in scope and any exceptions the auditor found.

Why it matters in a deal

In North America, SOC 2 Type II is often the first thing a client’s security team asks for. It complements ISO 27001: the certificate shows a management system exists, while the SOC 2 report gives detail on how specific controls performed. The availability criterion links to the provider’s uptime SLA, and testing evidence often references regular penetration testing. A provider that will not share its report under NDA is a warning sign. The United States guide covers what American buyers typically require.

Example

A Boston private equity firm sends a security questionnaire to two shortlisted rooms. Both say they are compliant, but only one sends a current Type II report covering twelve months with no exceptions on access controls. The other offers a Type I report from the previous year. The firm chooses the first and files the report with its vendor risk records.

Related terms