GlossarySecurity

SOC 2 (Type II)

An independent audit report on how a software vendor protects customer data, based on the AICPA Trust Services Criteria.

Full Definition

SOC 2 (System and Organization Controls 2) is an attestation framework developed by the AICPA that evaluates how a service organization protects customer data against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. A Type I report assesses whether controls are suitably designed at a single point in time; a Type II report additionally tests whether those controls operated effectively over an observation period, typically three to twelve months. SOC 2 is not a certification — it is a report issued by an independent CPA firm after an examination. Facility and IT teams use SOC 2 reports to vet software vendors that connect to building systems such as BAS and CMMS platforms. Syyclops is SOC 2 Type II compliant; the report is available under NDA through the Syyclops Trust Center.

Related Terms

Want to Learn More?

Explore how Syyclops uses these concepts to transform your infrastructure with digital twin technology.