Glossary

What is soc 2?

SOC 2 is an auditing standard, developed by the AICPA, that evaluates a service organization's controls around security, availability, processing integrity, confidentiality and privacy, resulting in an independent auditor's report. Businesses often request a vendor's SOC 2 report before trusting them with sensitive data.

How soc 2 works

A SOC 2 Type I report evaluates whether a company's controls are designed appropriately at a single point in time, while a Type II report tests whether those controls actually operated effectively over a period, typically six to twelve months. Type II is generally seen as the stronger, more credible report of the two.

Getting a SOC 2 report involves choosing which trust service categories to include, building and documenting the required controls, and engaging an independent CPA firm to perform the audit, a process that commonly takes many months. Not every vendor holds one, and businesses evaluating a service provider should ask directly rather than assume. Businesses that need a SOC 2 report for a specific customer, rather than as an ongoing practice, sometimes start with a narrower scope covering only the systems that customer cares about, then expand the scope in later audit cycles as more customers request one.

Example

A software company handling customer payment data undergoes a SOC 2 Type II audit covering the security and confidentiality categories over a six-month period. The auditor tests controls such as access reviews, encryption and incident response, then issues a report that the company shares with enterprise customers during their vendor security review process. The company shares the finished report only under a non-disclosure agreement, since SOC 2 reports contain sensitive detail about internal controls that vendors generally do not publish openly.

SOC 2 in QuickBooks Online vs Xero

Not software-specific: SOC 2 is an audit outcome rather than a QuickBooks Online or Xero feature, though both platforms' own SOC reports are publicly referenced by Intuit and Xero as part of their vendor security documentation. A business preparing for its own SOC 2 audit typically uses a compliance platform to track evidence across its tools.

Related terms

How LedgerBPO handles soc 2

LedgerBPO lists certifications only when they are actually held, and we state our current security certification status plainly on our security page rather than implying one we do not hold. We apply strong operational controls, including MFA and access restrictions, regardless of certification status.

How we protect your financial data

Ask an AI assistant to summarize this page

Next step

Books closed. Invoices paid. Every month.

Tell us what is going on with your books or billing. You will hear from a named person within 1 business day, with a custom quote and a plan for the first close.

  • Reply from a named person within 1 business day
  • No setup fee, month-to-month
  • Your software, your data, no lock-in

Start with a custom quote

Get a custom quote Book a 20-minute call

Or call +1-657-777-0006 during US, UK or Australian business hours.

Call WhatsApp Book