
Topic hub
The SOC 2 hub
Everything you need to make sense of SOC 2: the Trust Services Criteria, Type I versus Type II, the SOC 1 / 2 / 3 distinction, and how it sits alongside ISO 27001.
Guides
SOC 2, explained

What is SOC 2? The Trust Services Criteria and the report, explained
SOC 2 isn't a certificate you pass or fail. It's an independent auditor's report on how well your controls meet the Trust Services Criteria. Here's what that means and what's actually in it.
31 July 2026
SOC 2 Type I vs Type II: which report do you actually need?
A Type I is a snapshot; a Type II is a film. Type II carries the weight with enterprise buyers, but there's a sensible path between the two, plus the bridge letter that covers the gap.
31 July 2026
SOC 1 vs SOC 2 vs SOC 3: which SOC report do you need?
They sound like versions of the same thing. They aren't. SOC 1 is about your customers' financial reporting, SOC 2 is about security and trust, and SOC 3 is the public summary of a SOC 2.
31 July 2026Get SOC 2-ready with ResiliencePilot
See it on your own data and frameworks, with your security and data-residency questions answered.