Regulatory & compliance⏱ ~1 min

SOC 2

American audit standard (AICPA) for how a vendor handles customer data - the SOC 2 report is often what US and international enterprise buyers ask for instead of, or alongside, ISO 27001.

SOC 2 (System and Organisation Controls 2) is an audit standard developed by the American accounting body AICPA. It assesses a vendor's controls against five 'trustTrust - one of Tvimenning's core values and foundation for long-term customer relationships in the energy sector. service criteria': security, availability, processing integrity, confidentiality and privacy. The result is a SOC 2 report (Type I: the controls exist at a given point in time, or Type II: the controls have operated effectively over a period, typically 6-12 months) signed by an independent auditor. SOC 2 is not a certification in the same sense as ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. - it is an attestation report shared directly with customers under NDA, not a public mark.

Security