Procurement and Tooling
SOC 2
A US attestation reporting on controls relevant to security, availability, processing integrity, confidentiality and privacy, performed against the AICPA Trust Services Criteria. The report is issued by a licensed CPA firm, not by a certification body.
Why it matters: US buyers usually ask for SOC 2 where UK and EU buyers ask for ISO/IEC 27001, and the control overlap between them is substantial.
Related terms
Questions about how this applies to you? Book a free 45 minute diagnostic.
