First SOC 2 program
A credible starting point
Set an annual review date for critical and high-risk vendors and subscribe to their security advisories and status notices. At each review, obtain current assurance information, compare it with the prior year, revisit open findings, and confirm that data use and service reliance have not changed.