Logo Menu

Knowledge baseΒ·166 articles

Where do you want to start?

The SOC 2 library, organized by the decision in front of you. Pick a task to jump to its guides, or start from one of the essential reads below.

Choose your task

Essential reads

Audit Preparation December 10, 2025 18 min read

SOC 2 Controls List (2026): What Auditors Ask For

SOC 2 controls mapped to criteria, evidence examples, and common gaps. Download an editable starter matrix covering CC1–CC9, A1, PI1, C1, and P1–P8.

Read insight β†’
SOC 2 Basics December 6, 2025

SOC 2 Trust Services Criteria: 5 Categories & Scope

The five SOC 2 Trust Services Criteria explained: Security, Availability, Processing Integrity, Confidentiality, and Privacy, plus how to choose scope.

Read insight β†’
Compliance Tools January 19, 2026

Best SOC 2 Compliance Software by Buyer Fit (2026)

Compare the best SOC 2 compliance software by buyer fit, sourced pricing, tradeoffs, and audit handoff for startups, multi-framework teams, and enterprises.

Read insight β†’
Cost & Timeline December 17, 2025

SOC 2 Type 2 Audit Cost: First-Year and Renewal Budgets

Budget for a SOC 2 Type 2 audit: audit-only estimates, observation-period costs, first-year setup, renewal fees, and questions to ask before signing.

Read insight β†’
Framework Comparisons February 1, 2026 14 min read

SOC 2 vs ISO 27001 (2026): Which Should You Get First?

SOC 2 is the US standard; ISO 27001 is global. Get the one your biggest market asks for first. 2026 costs, timelines, control overlap, and which to pick.

Read insight β†’
Industry & Verticals March 9, 2026

SOC 2 for AI Companies (2026): What Auditors Test First

How auditors evaluate AI/ML companies under SOC 2 in 2026 β€” model governance, training-data lineage, prompt logging, and LLM subprocessor risk mapped to the Trust Services Criteria.

Read insight β†’