#vendor-risk

1 article found

SOC 2 Type 2 for SaaS: Trust Services Criteria, Observation Periods, and Reading the Report
#saas-compliance#security#data-governance

SOC 2 Type 2 for SaaS: Trust Services Criteria, Observation Periods, and Reading the Report

How SOC 2 Type 2 works for SaaS: the AICPA criteria, Type 1 vs Type 2 periods, bridge letters, subservice carve-outs, qualified opinions, and audit fees.

May 20, 202412 min read