| ▲ | Terretta 2 hours ago | |||||||||||||||||||||||||||||||||||||
Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they picked. Pick basic controls, it's cheaper to pass easily, and now you have a logo. This means SOC2s of either type cannot be compared to one another (and SOC2 Type 1 are roughly logo-ware). SOC3 is, roughly, SOC2 redacted. Recap: SOC2 Type 1 is a firm picking some controls to say they'll do them, SOC2 Type 2 is roughly a firm having someone look at whether they're doing that (warning, screenshots might suffice, audit verification is probably not what you think), and SOC3 is public or non-confidential water down of that, typically without findings. The only thing that matters is what controls, specifically, they're actually audited on. So ideally you want to know what the controls they picked are, and that a SOC2 Type 2 was audited on those. Btw, keep in mind that "end to end encryption" means "https" and most controls have similarly basic ways of achieving them. It's difficult to fail SOC2 Type 2 core controls if you know "don't be useless" is how you pass them. Also, it's not $50K even through the big five DIY SOC2 Type 2 shops. You can use the same ones trillion dollar firms use, by signing up online, and you'll be surprised how inexpensive relative to the cost of failing to let a business check that box in their procurement process. | ||||||||||||||||||||||||||||||||||||||
| ▲ | tptacek 18 minutes ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||
Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear. In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering. | ||||||||||||||||||||||||||||||||||||||
| ▲ | FinnKuhn 2 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||
I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a... | ||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||
| ▲ | deepsun 2 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||
Well you "claiming controls" to an independent CPA auditor. If a licensed CPA helps you lie -- they might lose their license (and can even get to prison), just like a tax preparer CPA can. | ||||||||||||||||||||||||||||||||||||||