What is SOC 2?
A US-originated audit framework — SOC 2 Type II — that attests a service provider has effective controls over security, availability, confidentiality, processing integrity, and privacy.
Also known as
SOC 2 — explained.
SOC 2 (Service Organization Control 2) is an audit framework developed by the AICPA (American Institute of Certified Public Accountants) for service providers handling customer data. The relevant variant for software vendors is SOC 2 Type II — an attestation by an independent auditor that the vendor's stated controls have operated effectively over a defined period (typically 6 or 12 months). The audit scope covers up to five Trust Service Criteria: Security (mandatory), Availability, Confidentiality, Processing Integrity, and Privacy. SOC 2 differs from ISO 27001 in two important ways: it is an attestation rather than a certification (the auditor issues a report; there is no certificate); and it is more US-centric in adoption, though increasingly recognised internationally. For SaaS and managed-service vendors selling into US enterprise procurement, SOC 2 Type II is effectively mandatory. Vendors hold the report under NDA and share it with prospects during procurement due-diligence.
Zeour solutions that operate on this layer.
Verticals where soc 2 is operationally critical.
Blog posts that go deeper on soc 2.
Adjacent definitions to read next.
ISO 27001
Compliance & DataThe international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.
GDPR
Compliance & DataThe EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.
HIPAA
Compliance & DataThe US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.
PCI DSS
Compliance & DataThe Payment Card Industry Data Security Standard — the security baseline that any system handling card data must meet.
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where soc 2 actually sits in your stack, then a fixed-fee Discovery price by the end of the call.