SOC 2 (pronounced “sock two”) stands for “Service Organization Control 2”. It’s a set of compliance priorities and criteria created by the American Institute of CPAs (AICPA) to ensure that sensitive customer data is stored in the cloud in a secure and compliant manner.
SOC 2 is a commonly accepted security standard that demonstrates the maturity of vendors who achieve this certification across a range of criteria. The qualities and processes that SOC 2 auditors measure should be a priority for any organization that handles sensitive data.
There are five Trust Services Criteria assessed as part of SOC 2 certification:
- Security
- Availability
- Confidentiality
- Processing Integrity
- Privacy
Of these, security is the only required criteria, and the most rigorous. Companies can choose which criteria they get certified in.