You are in control of your cookies

    Atlas uses strictly necessary cookies to keep you signed in. With your consent, we add anonymized product analytics, conversion attribution, and remembered preferences. Change your mind any time at /privacy/cookies.

    Off until you agree · Change it any time

    • Necessaryalways on
    • Analyticsopt-in
    • Marketingopt-in
    • Preferencesopt-in
    Atlas
    • All-in-one
    • Solutions
    • Compare
    • Pricing
    PricingGet started
    1. Atlas
    2. Glossary
    3. SOC 2

    Security & Compliance

    SOC 2

    SOC 2 is a widely recognized security compliance framework that verifies, through an independent audit, that a service provider properly protects customer data across principles like security and availability.

    Start freeBrowse the glossary
    • Also called: SOC 2 compliance, System and Organization Controls 2

    Definition

    What is SOC 2?

    SOC 2 is a widely recognized security compliance framework that verifies, through an independent audit, that a service provider properly protects customer data across principles like security and availability.

    SOC 2 (System and Organization Controls 2) was developed by the AICPA. It evaluates a company's controls against Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) with security required and the others optional.

    A SOC 2 report is produced by an independent auditor. A Type I report assesses controls at a point in time; a Type II report tests that they operated effectively over a period, usually several months to a year.

    For buyers, a SOC 2 report is common evidence that a vendor takes data protection seriously, which is why it is frequently requested during enterprise procurement and security reviews.

    See how Atlas connects it all

    Related reading

    • The Atlas platform
    • The all-in-one work OS
    • Pricing
    • Work OS glossary

    FAQ

    Questions, answered.

    What is the difference between SOC 2 Type I and Type II?
    Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether those controls actually operated effectively over a period, usually several months.
    Is SOC 2 a certification?
    Technically no. SOC 2 results in an audit report by an independent CPA firm, not a certificate, though people often speak of being SOC 2 compliant or SOC 2 audited.

    Ready when you are

    Put soc 2 to work in one platform.

    Atlas is the all-in-one work OS: tasks, projects, CRM, contracts, HR, and automation on one shared record, with a governed AI assistant. Start free.

    Get started freeSee pricing
    AtlasWork, planned itself.

    The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

    System status
    • SSO
    • SCIM
    • Two-factor sign-in
    • Audit log

    Product

    • Overview
    • PDF tools
    • Diagram tools
    • People & HR
    • Integrations
    • Marketplace
    • Pricing

    Resources

    • Guides
    • Glossary
    • Compare
    • Docs
    • API reference
    • Support
    • Changelog
    • Status

    Company

    • About
    • Careers
    • Press
    • Contact

    Legal & trust

    • Trust center
    • Security
    • Privacy
    • Terms
    • DPA
    • GDPR
    • SLA
    • Refunds
    • Google API data
    Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
    PrivacyTermsSecurityStatus