SOC 2
A report issued by an auditor against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 is a point-in-time design; Type 2 covers an operating period, typically 6-12 months.
SOC 2 is the report every B2B buyer asks for, and its identity content is predictable: access provisioning and removal, periodic access review, MFA, and logging. A Type 2 covering a real observation window is the one that means something, since a Type 1 only says the design existed on a given day. Read the exceptions section, not the opinion letter.
See also: compliance guides, access certification, deprovisioning, B2B SaaS identity
Related on Start with Identity
- GuideIAM Audit Preparation Guide: SOX, SOC 2, and HIPAA Readiness
Prepare for identity and access management audits with complete evidence collection, access review documentation, and compliance frameworks for SOX, SOC 2, and
- GuideSOC 2 for identity: the controls that actually matter
SOC 2 isn't prescriptive, it tests controls you've defined against the Trust Services Criteria. For identity, the controls auditors expect to find are: - Access
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GuideCustomer Identity Verification Guide: KYC, Document Verification, and Fraud Prevention
Implement customer identity verification with KYC processes, document verification, liveness detection, progressive profiling, and fraud prevention strategies.
- GlossaryFedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used
- GlossaryGDPR
General Data Protection Regulation. EU privacy law in force since 2018. Establishes user rights (access, rectification, erasure, portability) and obligations on