SOC is an audit framework for service organizations. If you handle customer data, clients will ask for your SOC report.
The Trust Service Criteria:
Security. Protection against unauthorized access (required).
Availability. Systems available as promised.
Processing Integrity. Accurate and authorized processing.
Confidentiality. Protected confidential information.
Privacy. Proper personal data handling.
Report types:
- Type I: Point-in-time design assessment
- Type II: Assessment over - months (preferred)