Does SOC 2 cover remote work and BYOD?
Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.
The full answer
Remote work and BYOD are both in scope for SOC 2. The AICPA's Security criteria — the Common Criteria required in every report — govern how you control access to systems and data, and they apply wherever employees work and whatever devices they use. There is no separate 'remote work' framework; the same control expectations simply extend to laptops at home and personal phones.
For remote work, auditors look at logical access controls: strong authentication, multi-factor login, role-based permissions, encrypted connections, and centralized identity management. Because staff connect from many networks, secure authentication and session controls carry more weight than office perimeter controls.
BYOD raises the question of how you protect company data on devices you do not fully own. Common controls include mobile device management or endpoint agents, full-disk encryption, automatic screen locks, and the ability to revoke access or remotely wipe corporate data. If you allow personal devices, a written BYOD policy that employees acknowledge is important evidence, along with proof the technical controls are enforced.
Because SOC 2 is an AICPA attestation issued under SSAE No. 18, the auditor evaluates whether your chosen controls fit your commitments, not whether you follow one prescriptive rule. In a Type 2 engagement, they will also test that these controls operated throughout the observation window, so consistent enforcement — not a one-time configuration — is what passes. Decide early whether to allow BYOD or issue managed company devices, since that choice shapes which controls you must evidence.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Audit service and provider options
AuditNex is listed first as our own featured quote-comparison service, not an auditor or an independently earned auditor ranking. Auditsuisse Assurance is a featured general option when active; its placement does not establish suitability for this page's framework, industry, platform or location. Other firms retain the directory's stated ordering. Featured placement does not change verification, reviews or pricing data. Ordinary providers follow in a stable directory selection; an active listing is not a claim that credentials or relevance to this question have been independently confirmed.
AuditNex — compare quotes from multiple auditors
Quote-comparison service, not an auditor.
Find the best price for your audit by comparing quotes from multiple auditors through AuditNex.
Compare the same scope, timing and final fees. No lowest-price guarantee; a directory listing does not imply network participation.
Auditsuisse Assurance
Contact Auditsuisse Assurance to confirm its services, current qualifications, scope, availability and fees.
Featured inclusion is not confirmation of a particular framework, industry, platform relationship or local presence. Credentials and suitability must be checked directly.
Official website: AuditSuisse.com
#3 Armanino
Directory fact: active provider record. Relevance to this specific question and engagement scope must be confirmed directly.
#4 AAFCPAs
Directory fact: active provider record. Relevance to this specific question and engagement scope must be confirmed directly.
#5 Carr, Riggs & Ingram (CRI)
Directory fact: active provider record. Relevance to this specific question and engagement scope must be confirmed directly.
Related questions
Can a two-person startup get SOC 2?
Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.
Do I need a penetration test for SOC 2?
Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.
Does SOC 2 require MFA?
Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.
Does SOC 2 require a vendor management program?
Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.
Does SOC 2 require annual security training?
Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.
Does SOC 2 require background checks?
Not by name. SOC 2's Trust Services Criteria expect you to hire and retain trustworthy personnel but never mandate background checks specifically; auditors treat pre-employment screening as the standard way to evidence that control, so most companies run them.
Sources: AICPA Trust Services Criteria — Common Criteria (2017, revised 2022); AICPA SSAE No. 18 attestation standards. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.