🍪 This website uses cookies

    We use cookies to operate our website, analyze traffic, and support marketing activities where permitted by law.
    Learn more in our Cookie Policy.

    GlossarySOC 2
    Glossary · Standard

    What is SOC 2?

    Definition

    SOC 2 is an audit standard developed by the American Institute of Certified Public Accountants (AICPA) that certifies a service provider's security, availability, processing integrity, confidentiality, and privacy controls. A SOC 2 Type II audit indicates the organization has maintained effective controls over a minimum six-month period. For learning platforms, SOC 2 certification is evidence of rigorous data security practices.

    ComplianceSecurity AuditData ProtectionTrustVendor AssessmentSOC 2
    In short

    SOC 2 at a glance.

    Independent audit of security controls
    Type I: point-in-time, Type II: 6+ months
    Required by many enterprise buyers
    Reduces procurement review burden

    SOC 2 and vendor selection

    Enterprise buyers increasingly require SOC 2 compliance from learning platform vendors. It demonstrates the vendor has invested in robust security, data protection, and operational controls. Pursuing SOC 2 requires ongoing commitment: audits occur annually and recertification is necessary. For vendors, SOC 2 is table stakes in enterprise sales.

    Learn more

    AI learning platform

    See how a modern, AI-native platform builds, delivers and tracks training — all in one place.

    Read the guide

    SOC 2 — frequently asked

    Type I is a point-in-time audit of controls at a specific date. Type II audits controls over a minimum six-month period, demonstrating sustained effectiveness. Type II is more rigorous and valued by enterprises.

    Audit fees range from $15,000 to $50,000+ depending on company size and complexity. Indirect costs include implementing controls, documentation, and staff time.

    SOC 2 verifies that controls are documented, implemented, and tested. It is a rigorous standard, but not a guarantee against all breaches. It is an important data point in vendor trust assessment.

    From definition to done.

    See AI learning platform in action — turn your knowledge into training, built and tracked with AI.