Last updated: July 26, 2026
Getting Ready · Compliance Q&A

Does SOC 2 require encryption at rest?

Not by a specific rule, but in practice yes. SOC 2's Security criteria expect you to protect stored data, and encryption at rest is the standard control auditors look for. Documenting a justified alternative is possible but uncommon.

The full answer

SOC 2 is criteria-based rather than a prescriptive checklist, so it does not name encryption at rest as a mandatory control the way some standards do. In practice, though, auditors treat it as the expected way to protect stored data under the Security criteria, and reports rarely pass without it or a well-justified alternative.

The relevant expectation is that you protect data commensurate with the risk and with the commitments you make to customers. Encryption at rest — plus encryption in transit — is the standard, widely recognized control for that job. If you scope in the optional Confidentiality criterion, the expectation is even stronger, because that criterion is specifically about safeguarding sensitive information.

The good news is that this is usually easy to satisfy. Major cloud providers encrypt storage, databases, and backups at rest by default, often with strong algorithms, so much of the control may already be in place. Your job is to confirm it is enabled everywhere sensitive data lives, manage the keys sensibly, and keep evidence such as configuration settings.

Because SOC 2 is an AICPA attestation issued under SSAE No. 18, the auditor evaluates whether your control meets your stated commitments, not whether you ticked a fixed box. If you genuinely cannot encrypt a particular data store, you can document a compensating control and the rationale, but that path is uncommon and invites scrutiny. For most companies, turning on and verifying encryption at rest is the simplest way to clear this expectation.

Go deeper

Short answer not enough? These pages cover the full picture:

Complete SOC 2 guide ›  ·  SOC 2 timeline estimator ›

Get matched with the right auditor

Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.

Get instant pricing →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

Can a two-person startup get SOC 2?

Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.

Do I need a penetration test for SOC 2?

Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.

Does SOC 2 cover remote work and BYOD?

Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.

Does SOC 2 require MFA?

Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.

Does SOC 2 require a vendor management program?

Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.

Does SOC 2 require annual security training?

Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.

All compliance questions ›

Sources: AICPA Trust Services Criteria — Security and Confidentiality (2017, revised 2022); AICPA SSAE No. 18 attestation standards. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.