There are two forms. A Type I report describes a company's controls at a single point in time and confirms they are suitably designed. A Type II report goes further: the auditor observes those controls operating over a period, typically several months, and reports on whether they worked consistently. Type II is the one buyers usually want, because designing a control and actually running it are different things.
SOC 2 is not a certification with a pass mark, and it is not a legal requirement. It is an attestation report, and what it covers depends on which criteria the company chose to include. When a vendor tells you they are SOC 2 examined, the useful follow-up questions are which type, which criteria, and how recent the report is.
It matters for website tools because a chat widget sits on your site and holds contact details for people who enquired. Clerkzo has been through a SOC 2 Type II examination, which is usually the piece of evidence a practice manager or IT reviewer asks for before approving a new tool.
Related terms
Browse all 142 terms- Personally Identifiable Information (PII)Personally identifiable information (PII) is any data that can identify a specific individual on its own or when combined with other information — names, email addresses, phone numbers, account identifiers and more.
- Data RetentionData retention is the policy and practice of deciding how long you keep each type of data before deleting it, based on how long you actually need it and what the law requires or permits.
- Data ResidencyData residency refers to the country or region where an organisation's data is physically stored, and to any requirement that it stay within a particular jurisdiction.
- Encryption at RestEncryption at rest means data is stored in an encrypted form, so that anyone who obtains the underlying storage — a disk, a backup, a database file — cannot read it without the decryption key.