Skip to main content

attestation

SOC 2 evidence across 0 vendors

SOC 2 is an attestation report, not a certification. A CPA firm examines controls against the AICPA trust services criteria and issues a restricted-use report for a period. CertReports indexes what is public: the report type, period and auditor where the vendor or a registry states them, plus the CSA STAR Level 2 attestations built on SOC 2 examinations.

Verified rows
0
Vendor-stated
27
Expired
0
Last verified
17 Sep 2026

No vendor carries registry or auditor verified SOC 2 evidence yet.

Type I versus Type II

A Type I report describes controls at a point in time. A Type II report tests them over a period, commonly six to twelve months. Most buyers ask for Type II covering the last twelve months, or an older report with a bridge letter of at most three months.

Why nobody is "SOC 2 certified"

The AICPA issues no certificate and keeps no registry of audited organisations. A vendor that says "SOC 2 certified" usually means it has a report; CertReports records the report claim and flags the terminology.

How to get the report

SOC 2 reports are shared under NDA through the vendor trust centre. CertReports links to the request flow and never hosts, caches or summarises the report beyond facts the vendor has already published.