Remix.run Logo
FinnKuhn 2 hours ago

I think companies like Deel showed that SOC2 is more show than anything else.

For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

paulryanrogers 2 hours ago | parent | next [-]

Hasn't Deel been run out of business though?

IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.

FinnKuhn an hour ago | parent [-]

Their website is still up, but I have a hunch you can find some other certificate mill that will give you a SOC2 certificate just as easily.

a-priori an hour ago | parent | prev [-]

A SOC2's quality entirely depends on how much you trust the auditing firm.

Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.

But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.

FinnKuhn 40 minutes ago | parent | next [-]

These audits for Apple were done by EY.

As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.

https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...

tptacek 27 minutes ago | parent | prev [-]

Not really. The more expensive the auditor, the more they'll work with you to craft something that will avoid exceptions. There's no real "rigor" involved in SOC2! The "audit" here is in audit in the accounting sense: "do your records square up?". SOC2 auditors are generally not technical people.