SOC 2
An audit report on how a service organization controls customer data, assessed against the Trust Services Criteria.
It is not a certification but an auditor's opinion, produced by a licensed CPA firm. Type 1 assesses whether controls are suitably designed at a point in time; Type 2 tests whether they operated effectively over a period, usually six to twelve months.
Buyers increasingly ask for it before signing, which is why it has become a sales requirement for technology companies as much as a security exercise.
Where this comes up
SOC 2 sits inside our compliance and frameworks work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.