Short answer
SOC 2 is an independent audit report, defined by the AICPA, on how a service organization protects customer data. It assesses controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Type I reports test control design at a point in time; Type II reports test how controls operated over a period.
SOC 2 explained
Financial firms ask CRM, AI and consulting vendors for SOC 2 Type II reports as part of vendor due diligence. Reading the report means checking its scope, the period covered, any exceptions the auditor found, and the complementary user entity controls, which are the controls the customer is expected to run themselves.
Salesforce, HubSpot, Anthropic and OpenAI all make SOC 2 reports for their services available to customers through their trust portals.
How Vantage Point helps: we help firms map vendor SOC 2 reports to their own controls and configure the customer-side controls those reports assume.
Frequently asked questions
What is the difference between SOC 2 Type I and Type II?
Type I tests whether controls are designed properly at one point in time. Type II tests whether they operated effectively over a period, usually six to twelve months.
Is SOC 2 a certification?
Not strictly. It is an attestation report issued by an independent CPA firm, not a certificate.
