SOC 2 Compliance
A security framework for service organizations developed by the AICPA, requiring controls around security, availability, confidentiality, and privacy of customer data.
SOC 2 (System and Organization Controls 2) is a compliance framework developed by the American Institute of CPAs (AICPA). It evaluates how well a service organization manages customer data based on five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
SOC 2 compliance is increasingly required by enterprise customers before they’ll trust a vendor with their data. The audit examines policies, procedures, and technical controls over a period of time (Type II) or at a point in time (Type I).
Password management is directly relevant to SOC 2: auditors examine how credentials are stored, shared, rotated, and logged. Using a team password manager with access controls and audit trails helps demonstrate the controls SOC 2 requires.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide