SOC (System and Organization Controls) certification is a standard developed by the American Institute of Certified Public Accountants (AICPA) to ensure that organizations have adequate controls and processes in place to protect sensitive information. SOC certification is a critical element of compliance for organizations that store, process, or transmit sensitive information, such as financial data, healthcare information, or personally identifiable information (PII).
There are two types of SOC certifications: SOC 2 and SOC 3. SOC 2 reports focus on a company's controls over information systems that affect the security, availability, processing integrity, confidentiality, and privacy of customer data. SOC 3 reports are public summaries of SOC 2 reports and are intended to be used by organizations that need assurance of a company's controls without requiring access to the full SOC 2 report.