Overview
SOC 2 audits controls relating to security, availability, processing integrity, confidentiality and privacy. It is the standard for modern digital service providers.
To whom is the standard relevant?
- IT service providers
- Companies with high security requirements
- Typical companies include:
- SaaS providers
- Cloud service providers
- Managed service providers
- Hosting providers
- Data centres
- FinTechs
- HealthTech companies
- Platform providers
- Software companies
- AI and data platforms
What is audited?
SOC 2 is based on the Trust Services Criteria (TSC).
The five Trust Services Criteria
| Criterion | Objective |
Security | Protection of systems against unauthorised access |
Availability | Availability of systems in accordance with commitments |
Processing Integrity | Complete and accurate processing |
Confidentiality | Protection of confidential information |
Privacy | Protection of personal data |
Note: Security is mandatory for every SOC 2 report. The other criteria are included depending on the services provided and customer requirements.
Scope of services
- Audit of the Trust Services Criteria
- Type 1: design assessment
- Type 2: effectiveness assessment over a period of time
- Readiness assessment
- Optional: SOC 2 + BSI C5 + GDPR as a multi-standard report
Benefits
- Strong evidence of security
- Competitive advantage in the IT market, for example in tenders
- Ideal for international clients
- Transparency over the control system
- Support for sales activities
