SOC 2 is an audit and reporting framework from the AICPA, based on the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy), under which an independent CPA firm examines a service organization's controls and issues a report. Type I assesses control design at a point in time; Type II assesses operating effectiveness over a period. SOC 2 reports are the default security assurance US SaaS and API vendors provide to enterprise buyers.
SOC 2
SOC 2 is the security assurance a US enterprise buyer asks for first. It is not a certification but an attestation: an independent CPA firm examines a service organization’s controls against the Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and writes a report.
- Type I vs Type II - Type I judges whether controls are well designed at a moment; Type II judges whether they actually operated over a period, which is the one buyers want.
- The Trust Services Criteria - Five categories, of which ‘security’ is required and the others are included as relevant.
- A report, not a badge - The deliverable is a document a prospect’s security team reads under NDA, not a public certificate.
SOC 2 is close to universal across the payments and health-data platforms I score, which is exactly why it is a weak discriminator and I treat it accordingly. It tells a procurement team the vendor runs real controls; it says nothing about whether the API publishes scopes, examples, idempotency, or a consent surface. Separating ‘compliant’ from ‘usable by a developer or an agent’ is the whole job of the Kin Score, and the ubiquity of SOC 2 is a good illustration of why the two must be scored apart.
Referenced in API Evangelist papers
This standard shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this standard in the context of a real sector.
The State of US Payments APIs
SOC 2 is a near-universal trust-center signal across the payments cohort.
The State of US Healthcare APIs
SOC 2 is one of the common compliance attestations among health-data platforms.