Knowledge baseLibrary
SOC 2 guides
Vendor-neutral guides to SOC 2 as a European software or service company actually meets it: through a customer contract, on someone else's calendar, with a report you are not allowed to issue yourself.
Library
All guides
-
Does SOC 2 require a penetration test?
No criterion names one. Three other parties do, and one of them writes the report. Here is exactly where the expectation comes from and what it costs to ignore it.
Read -
Who can issue a SOC 2 report in the EU?
A CPA firm, performing an examination under the AICPA attestation standards. Not a platform, not a security firm, and not anybody selling you a certificate.
Read -
SOC 2 or ISO/IEC 27001 for an EU vendor?
One is an American report your US customers know by name. The other is the certificate European buyers actually write into tenders. The evidence for that, and how to choose.
Read -
SOC 2 penetration test: scope, timing and the report
What to put in scope, where the test lands relative to the observation window, and what the report has to contain before an auditor or a customer will treat it as evidence.
Read