SOC2
Audit framework proving security/availability/confidentiality controls exist and are followed — mostly a B2B/enterprise-sales requirement. Moved here from Regulatory/ since it's an attestation/audit standard, not a law.
Why we need this / what value this brings
The de facto standard enterprise B2B customers ask for as proof of security practices — not having it can silently block deals.
When to use this
Once an enterprise sale or partnership explicitly requires it — not worth pursuing speculatively pre-revenue.
How to use or implement this
Start with a Type I (point-in-time) readiness assessment before committing to a Type II audit, which requires controls to have been running over a period.
Research questions
- Not relevant pre-revenue, but worth knowing what it requires before it becomes a sales blocker with enterprise provider partners.
Empty folder — drop notes, links, and findings here as you research.