What is SOC 2?
SOC 2 (AICPA Trust Services Criteria). EU-based B2B SaaS selling into the US enterprise market, where SOC 2 reports are routinely demanded in procurement alongside ISO 27001.
Who needs to comply
- EU-based B2B SaaS expanding into the US market
- Data-platform and developer-tool companies serving US enterprises
- AI / ML platforms whose customers ask for SOC 2 alongside ISO 27001
- Healthcare-adjacent SaaS targeting US providers (often combined with HIPAA)
Key SOC 2 controls covered by Dazr
What auditors look for
SOC 2 Type 2 auditors sample evidence over the audit period (typically 6 to 12 months): access reviews actually happened, changes were peer-reviewed, incidents were logged, vendors were reviewed. Dazr is the system of record across the period.
How Dazr helps with SOC 2
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. SOC 2 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:
- Hold the Trust Services Criteria with linked controls and evidence
- Run quarterly access reviews on cadence with email reminders
- Track change management approvals and peer review evidence
- Keep vendors in the vendor register with DPA and SOC 2 / ISO links and review dates
- Hand the auditor a read-only view for sampling, or a single-PDF audit trail
Back to the full Dazr Compliance overview › | Sign up free ›