Skip to content
Find my data room
Data room terms / Security and compliance

SOC 2

The short version

An attestation from a licensed CPA firm, under AICPA rules, that a software company's security controls are designed well (Type I) or also worked over several months (Type II). Extra criteria such as availability or privacy can be added.

How it plays out on a deal

Procurement and IT security teams at banks, law firms and listed companies routinely put this report on their vendor checklist, because a Type II opinion shows controls operating across months rather than on the day of the audit.

Scope is where reports differ. Some describe the vendor's product, people and processes; others lean on the cloud host's attestation for the data center layer, and any report may list auditor exceptions. Request the most recent copy, usually shared under a confidentiality agreement, and read the period, the systems in scope and the exceptions section.

What to check in a review or demo

  1. 1Whether the report is Type I or Type II, and the dates it covers.
  2. 2Whether it covers the data room application itself or only the hosting environment.
  3. 3Whether the auditor noted exceptions, and how the vendor responded.

SOC 2: where the reviewed providers stand

Based on the certifications and attestations each provider lists publicly, as recorded in our review data. Ask for the current report or certificate and check its scope before relying on it.

Read alongside

Where this comes up on Data Room Review