SOC 2

Also known as: SOC 2 Type II, Service Organization Control 2

An audit report on a service provider’s controls over security and, optionally, availability, processing integrity, confidentiality, and privacy.

A SOC 2 report is produced by an independent auditor and describes whether a service organization’s controls are suitably designed, and in a Type II report, whether they operated effectively over a review period.

In healthcare vendor risk assessment, SOC 2 Type II is the most commonly requested evidence after a Business Associate Agreement.

Type I and Type II are not interchangeable. Type I describes control design at a point in time; Type II tests operation over months. A vendor offering a Type I report in response to a Type II request has answered a different question, and experienced reviewers notice.

The scope section matters as much as the opinion. A report that excludes the product the buyer is actually purchasing is common and easy to miss.