← Back to glossaryGlossary

SOC 2 Type II

Reviewed 19 July 2026Canonical definitionPart of: Agent Evaluation Terms →

SOC 2 Type II is an independent audit report that evaluates whether a service organisation's controls around security, availability, processing integrity, confidentiality, and privacy were operating effectively over a defined observation period, typically six to twelve months. Unlike SOC 2 Type I, which assesses design at a point in time, Type II assesses operating effectiveness over time. AI platforms and agent governance tools are increasingly required by enterprise customers to hold SOC 2 Type II certification.

§01 / QUESTIONSterm: SOC 2 Type II
Questions

Common questions.

What is SOC 2 Type II?

SOC 2 Type II is an independent audit report that evaluates whether a service organisation's controls around security, availability, processing integrity, confidentiality, and privacy were operating effectively over a defined observation period, typically six to twelve months.

How does SOC 2 Type II work?

Unlike SOC 2 Type I, which assesses design at a point in time, Type II assesses operating effectiveness over time. AI platforms and agent governance tools are increasingly required by enterprise customers to hold SOC 2 Type II certification.

Which terms are related to SOC 2 Type II?

Closely related concepts include SOC 2 (Service Organization Control 2), Agentic RAG, Continuous Integration Agent, Reflection Agent. Each is defined in the Prefactor glossary.

§02 / RELATEDnext: where this fits

See how every agent performs, and make it better

Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.