Skip to main content

Procurement and Tooling

SOC 2

A US attestation reporting on controls relevant to security, availability, processing integrity, confidentiality and privacy, performed against the AICPA Trust Services Criteria. The report is issued by a licensed CPA firm, not by a certification body.

Why it matters: US buyers usually ask for SOC 2 where UK and EU buyers ask for ISO/IEC 27001, and the control overlap between them is substantial.

Questions about how this applies to you? Book a free 45 minute diagnostic.

Back to the glossary

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.