Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves.
SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).
Both may also allow general lag time.
Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they picked. Pick basic controls, it's cheaper to pass easily, and now you have a logo.
This means SOC2s of either type cannot be compared to one another (and SOC2 Type 1 are roughly logo-ware).
SOC3 is, roughly, SOC2 redacted.
Recap:
SOC2 Type 1 is a firm picking some controls to say they'll do them, SOC2 Type 2 is roughly a firm having someone look at whether they're doing that (warning, screenshots might suffice, audit verification is probably not what you think), and SOC3 is public or non-confidential water down of that, typically without findings.
The only thing that matters is what controls, specifically, they're actually audited on. So ideally you want to know what the controls they picked are, and that a SOC2 Type 2 was audited on those.
Btw, keep in mind that "end to end encryption" means "https" and most controls have similarly basic ways of achieving them. It's difficult to fail SOC2 Type 2 core controls if you know "don't be useless" is how you pass them.
Also, it's not $50K even through the big five DIY SOC2 Type 2 shops. You can use the same ones trillion dollar firms use, by signing up online, and you'll be surprised how inexpensive relative to the cost of failing to let a business check that box in their procurement process.
I think companies like Deel showed that SOC2 is more show than anything else.
For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
Delve. Not Deel. Very different startups.
Hasn't Deel been run out of business though?
IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals.
Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.
Right, Delve was the company I was thinking of. Thanks for pointing that out.
Their website is still up, but I have a hunch you can find some other certificate mill that will give you a SOC2 certificate just as easily.
A SOC2's quality entirely depends on how much you trust the auditing firm.
Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.
But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.
These audits for Apple were done by EY.
As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.
https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...
Not really. The more expensive the auditor, the more they'll work with you to craft something that will avoid exceptions. There's no real "rigor" involved in SOC2! The "audit" here is in audit in the accounting sense: "do your records square up?". SOC2 auditors are generally not technical people.
> SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).
Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have.
Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that.
So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test.
A $50k audit is going to be team of 2 CPAs collecting evidence for 2 weeks.
Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear.
In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.
From my 8 years of working SOC2 Type 2 audits done by PwC for a large PaaS Cloud with a worldwide presence (not the big 3) saying Type 2 is almost as trivial as type 1 is absolutely false. This might be true for someone running their own low volume SaaS in one region but for someone the size of Apple they are investing a lot of resource to stay on top of the controls, especially patching and permissions. If you've invested heavily in homogenization and automation your less likely to fail and the audits will be simpler. Even with significant investment I expect there are many aging corners in any "cloud" that make audits subject to failure and require a lot of work to avoid qualifying exceptions.
I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering.
I wrote an article about this, and I think it's the Correct advice for virtually every startup thinking about SOC2:
https://fly.io/blog/soc2-the-screenshots-will-continue-until...
A few years before that, I wrote an article about what we learned from the consulting practice we ran building SOC2-supporting security programs for startups:
https://www.latacora.com/blog/2020/03/12/soc2-starting-seven...
I've had the experience, many times, of offering this advice in some forum and having someone try to rebut it, claiming that SOC2 is difficult, or that real customers will pick a SOC2 attestation apart with a fine-toothed comb looking for shortcuts you took, or that they built their whole security practice around SOC2. I can go all 12 rounds with someone on any of those points, but I think you can get most of my take from those two posts.
It doesn't look like fly.io publicly disclose who there auditor is so it is hard to judge that specific part of your experience. I'm not disagreeing with your perspective on startups. I'm saying that type 2 gets much harder when you are large. non-homogenous and lack sufficient automation and monitoring.
Our auditor is Aprio.
Well you "claiming controls" to an independent CPA auditor. If a licensed CPA helps you lie -- they might lose their license (and can even get to prison), just like a tax preparer CPA can.