Procurement Glossary

SOC 2

SOC 2 means security control report for vendors. Learn why it matters when buying, renewing, or replacing business software.

Plain-English meaning

A SOC 2 report is an independent attestation report about controls relevant to selected Trust Services Criteria for a defined system and period.

Why it matters in a software decision

It can provide useful evidence, but the report's scope, period, criteria, exceptions, and complementary user controls determine relevance.

Where you may see it

Vendor trust centers, controlled document exchanges, security reviews, and audit evidence repositories.

What to verify

  • Report type and period
  • System and service scope
  • Exceptions and management responses
  • Complementary user and subservice controls

Do not confuse it with

SOC 2 is an attestation report, not a product certification or a guarantee that every security requirement is met.

Procurement example

A reviewer should connect the report scope to the purchased service and record any gap requiring other evidence.

This glossary explains procurement usage in plain English. Contract, privacy, security, accounting, and regulatory conclusions require context-specific review.