Skip to content

Glossary · Compliance & Regulation

SOC 2

Also known as: SOC 2 Type II

Short answer

SOC 2 is an independent audit report, defined by the AICPA, on how a service organization protects customer data. It assesses controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Type I reports test control design at a point in time; Type II reports test how controls operated over a period.

SOC 2 explained

Financial firms ask CRM, AI and consulting vendors for SOC 2 Type II reports as part of vendor due diligence. Reading the report means checking its scope, the period covered, any exceptions the auditor found, and the complementary user entity controls, which are the controls the customer is expected to run themselves.

Salesforce, HubSpot, Anthropic and OpenAI all make SOC 2 reports for their services available to customers through their trust portals.

How Vantage Point helps: we help firms map vendor SOC 2 reports to their own controls and configure the customer-side controls those reports assume.

Frequently asked questions

What is the difference between SOC 2 Type I and Type II?

Type I tests whether controls are designed properly at one point in time. Type II tests whether they operated effectively over a period, usually six to twelve months.

Is SOC 2 a certification?

Not strictly. It is an attestation report issued by an independent CPA firm, not a certificate.

Last reviewed October 2, 2026 by the Vantage Point team. Browse all glossary terms →