← Back to glossary Glossary

SOC 2 Type II

Reviewed 19 July 2026 Canonical definition Part of: Agent Evaluation Terms →

SOC 2 Type II is an independent audit report that evaluates whether a service organisation's controls around security, availability, processing integrity, confidentiality, and privacy were operating effectively over a defined observation period, typically six to twelve months. Unlike SOC 2 Type I, which assesses design at a point in time, Type II assesses operating effectiveness over time. AI platforms and agent governance tools are increasingly required by enterprise customers to hold SOC 2 Type II certification.

§01 / QUESTIONSterm: SOC 2 Type II
Questions

Common questions.

What is SOC 2 Type II?

SOC 2 Type II is an independent audit report that evaluates whether a service organisation's controls around security, availability, processing integrity, confidentiality, and privacy were operating effectively over a defined observation period, typically six to twelve months.

How does SOC 2 Type II work?

Unlike SOC 2 Type I, which assesses design at a point in time, Type II assesses operating effectiveness over time. AI platforms and agent governance tools are increasingly required by enterprise customers to hold SOC 2 Type II certification.

Which terms are related to SOC 2 Type II?

Closely related concepts include SOC 2 (Service Organization Control 2), Agentic RAG, Reflection Agent, Structured Output (AI). Each is defined in the Prefactor glossary.

§02 / RELATEDnext: where this fits
Keep reading

Where this fits.

See how every agent performs, and make it better

Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.