SOC 2 – The international standard for trust in digital services

Overview 

SOC 2 audits controls relating to security, availability, processing integrity, confidentiality and privacy. It is the standard for modern digital service providers. 

To whom is the standard relevant? 

  • IT service providers
  • Companies with high security requirements
  • Typical companies include:
    • SaaS providers
    • Cloud service providers
    • Managed service providers
    • Hosting providers
    • Data centres
    • FinTechs
    • HealthTech companies
    • Platform providers
    • Software companies
    • AI and data platforms

What is audited? 

SOC 2 is based on the Trust Services Criteria (TSC). 

The five Trust Services Criteria 

CriterionObjective

Security 

Protection of systems against unauthorised access 

Availability 

Availability of systems in accordance with commitments 

Processing Integrity 

Complete and accurate processing 

Confidentiality 

Protection of confidential information 

Privacy 

Protection of personal data 


Note: Security is mandatory for every SOC 2 report. The other criteria are included depending on the services provided and customer requirements. 

Scope of services 

  • Audit of the Trust Services Criteria
  • Type 1: design assessment
  • Type 2: effectiveness assessment over a period of time
  • Readiness assessment
  • Optional: SOC 2 + BSI C5 + GDPR as a multi-standard report

Benefits 

  • Strong evidence of security
  • Competitive advantage in the IT market, for example in tenders
  • Ideal for international clients
  • Transparency over the control system
  • Support for sales activities

FAQ