SOC 2 compliance guide
What SOC 2 actually requires, the difference between Type I and Type II, the Trust Services Criteria — and a practical 90-day path written for SaaS teams without a compliance department.
What SOC 2 actually requires, the difference between Type I and Type II, the Trust Services Criteria — and a practical 90-day path written for SaaS teams without a compliance department.
SOC 2 (Service Organization Control 2) is an attestation report — not a certificate — issued by a licensed CPA firm under AICPA standards. It describes how your service organisation meets the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
In practice, SOC 2 has become the default North American answer to "is your SaaS safe to buy?" — comparable to what ISO 27001 is in the rest of the world.
Most growing SaaS companies end up doing both. The control overlap is huge — running two separate spreadsheets means writing every policy twice and answering every customer question twice.
ISO-STANDARD.app ships a ready-to-adopt SOC 2 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.