SOC 2 Type II
Audited controls for security, availability & confidentiality
SOC 2 Type II across all five Trust Service Criteria
Independently audited annually by a Big 4 firm. Security, Availability, Processing Integrity, Confidentiality, and Privacy — all five TSCs in scope, with Type II operating-effectiveness coverage over a 12-month window.
Overview
SOC 2 Type II is the AICPA's benchmark for evaluating a service organization's controls over time. VxCloud maintains a SOC 2 Type II report audited annually by a Big 4 accounting firm, covering all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The audit observation window is 12 months — the auditor evaluates not just that controls exist, but that they operated effectively every day of the period.
The report covers controls over access management, change management, system operations, risk assessment, logical and physical security, encryption, vendor management, incident response, and business continuity. It's available to customers and prospective customers under NDA — request through your CSM or sales contact. Sub-service organizations (cloud providers, critical SaaS vendors) are listed in the report's carve-out section.
What's included
Production-grade capabilities, ready to enable in your workspace.
All 5 TSCs in scope
Security, Availability, Processing Integrity, Confidentiality, Privacy — not just the security TSC.
Big 4 auditor
Audited by one of the Big 4 accounting firms. Report is accepted by every major enterprise procurement team.
Annual renewal
Continuous audit coverage with no gaps. Every customer contract year has an unexpired Type II report available.
Evidence automation
Internal controls are instrumented with automated evidence collection, reducing audit fatigue for customers and auditors.
Subprocessor transparency
Every subprocessor is listed, their purpose documented, and their own compliance attestations tracked.
Continuous monitoring
Between audits, internal controls are monitored continuously and deviations trigger remediation workflows.
Business outcomes
Measurable impact teams see when they adopt soc 2 type ii.
Major enterprise procurement coverage
SOC 2 Type II clears the security section of virtually every enterprise vendor risk questionnaire.
Time to receive report under NDA
Request through your CSM; executed NDAs return a report the same business day in most cases.
Type II observation window
Continuous evidence of control effectiveness, not a point-in-time snapshot.
Audit gaps between annual cycles
Overlapping observation windows ensure every customer contract period has a valid unexpired report.
How customers use it
Real scenarios from VxCloud customers across regulated industries and fast-moving teams.
Broker-dealer vendor risk review
SOC 2 Type II + SOC 1 Type II cover IT general controls expected by FINRA examiners.
Hospital vendor onboarding
SOC 2 + HIPAA BAA satisfies the security, availability, and confidentiality controls required by CE security officers.
B2B SaaS selling into Fortune 500
Downstream customers' security teams accept the SOC 2 report as sufficient evidence for their own SOC 2 vendor-management control.
State government procurement
SOC 2 satisfies most state IT security questionnaires; paired with FedRAMP for federal workloads.
Frequently asked questions
Still have questions? Our enterprise team answers within one business day.
Contact your Customer Success Manager or sales representative. Reports are provided under a mutual NDA and are available to active customers, prospective customers in active sales cycles, and customer auditors.
Related enterprise capabilities
Ready to move forward with SOC 2 Type II?
Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.