Start with Identity
← Glossary
Compliance

SOC 2

A report issued by an auditor against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 is a point-in-time design; Type 2 covers an operating period, typically 6-12 months.

SOC 2 is the report every B2B buyer asks for, and its identity content is predictable: access provisioning and removal, periodic access review, MFA, and logging. A Type 2 covering a real observation window is the one that means something, since a Type 1 only says the design existed on a given day. Read the exceptions section, not the opinion letter.

See also: compliance guides, access certification, deprovisioning, B2B SaaS identity

Last reviewed By SWI Community TeamSuggest a correctionHow we research