Does SOC 2 require a vendor management program?
Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.
The full answer
SOC 2 does not include a checklist item literally titled 'vendor management,' but the AICPA's Common Criteria address risks arising from vendors and subservice organizations. Because those criteria are mandatory in every report, auditors will expect to see how you identify, evaluate, and monitor the third parties that touch your systems and data.
In practice, that means keeping a current vendor inventory, tiering vendors by the risk they pose, and performing due diligence before onboarding. For critical providers such as your cloud host, reviewing their own SOC 2 report is the common form of evidence — those reports are confidential and shared under NDA. Contracts should include security and confidentiality obligations, and you should re-review important vendors periodically, not just once.
The depth of the program scales with your size and risk. A small startup can run a lightweight process in a spreadsheet or GRC platform, while a company handling regulated data will formalize approvals and monitoring. Buyers typically treat a SOC 2 report as current for 12 months from its period end, so collect and refresh your vendors' reports on that cadence.
Because SOC 2 is an AICPA attestation issued under SSAE No. 18, the auditor judges whether your vendor controls are designed and operating appropriately for your business — not whether you followed one rigid template. Start with the vendors that access customer data, document your review steps, and keep the evidence where you can retrieve it during fieldwork.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Can a two-person startup get SOC 2?
Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.
Do I need a penetration test for SOC 2?
Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.
Does SOC 2 cover remote work and BYOD?
Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.
Does SOC 2 require MFA?
Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.
Does SOC 2 require annual security training?
Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.
Does SOC 2 require background checks?
Not by name. SOC 2's Trust Services Criteria expect you to hire and retain trustworthy personnel but never mandate background checks specifically; auditors treat pre-employment screening as the standard way to evidence that control, so most companies run them.
Sources: AICPA Trust Services Criteria — Common Criteria (2017, revised 2022); AICPA SSAE No. 18 attestation standards; Standard procurement practice — SOC 2 report validity (2026). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.