Last updated: July 26, 2026
SOC 2 by Industry

SOC 2 Audits for Hosting Providers

Companies running their websites, applications, and managed servers on your infrastructure depend on you to stay up and keep their data isolated — so their security and procurement teams expect a SOC 2 before they migrate. Here is how hosting providers scope the audit — criteria, the data-center question, controls, and cost.

Why hosting providers get asked for SOC 2

Hosting providers are foundational vendors: if you run web and application hosting, managed servers, or colocation-adjacent SaaS, your customers' uptime is your uptime and your customers' data isolation is your responsibility. Because you sit beneath everything they serve, their vendor-risk teams and their own auditors ask for a SOC 2 as a matter of course, and Availability tends to be a headline concern rather than an afterthought — an outage on your platform is directly visible to their users.

The evaluation is unusually infrastructure-heavy. Reviewers want to understand physical security and environmental controls of the facilities, logical isolation between tenants on shared hosts, patching and hardening of the underlying platform, and how you handle backups, capacity, and disaster recovery. A recurring question is whether the data centers themselves are inside your report or carved out to a colocation or cloud provider — and how you evidence the controls you don't physically own.

Trust Services Criteria focus for Hosting Providers

Security (the Common Criteria) is mandatory in every SOC 2 report. The other four criteria are elective — you scope them in based on what your customers actually rely on. Here is how hosting providers typically scope them, and why:

CriterionTypical scopeWhy it matters in Hosting Providers
SecurityAlways in scopeMandatory in every SOC 2. For hosting, expect scrutiny on tenant isolation across shared servers, hardening and patching of the underlying platform, and access controls over hypervisors, management consoles, and customer data stores.
AvailabilityAlways in scopeEffectively core for this category: customers buy hosting for uptime, so reviewers expect SLAs backed by tested redundancy, capacity planning, monitored failover, and evidence of a real disaster-recovery exercise.
ConfidentialityCommonYou store customer applications, databases, and backups. Reviewers look for classification, encryption at rest and in transit, and retention and secure-disposal controls over the data hosted on your platform.
Processing IntegritySometimesScoped in when customers rely on managed services such as backups or migrations completing accurately and completely. Pure infrastructure hosting often treats this as reliability and leaves the criterion out.
PrivacyRarely includedUncommon for infrastructure providers, since you host data on customers' behalf rather than determining its use. Most hosting providers address data protection through Security and Confidentiality controls instead.

Each elective criterion adds controls and evidence — and cost. Scope what your customers demand in security reviews, not everything at once.

Scoping decisions specific to Hosting Providers

These are the Hosting Providers-specific calls that shape your system description, control list, and ultimately your audit price. Settle them before you request quotes — firms price scope, not industry labels.

Decide the carve-out vs inclusive method for data centers

If you run in colocation or on a cloud provider, you typically carve out the facility as a subservice organization and rely on its SOC report for physical and environmental controls. If you own the data centers, an inclusive approach puts those controls in your own report. Settle this first — it defines what your auditor tests directly versus what they rely on from others.

Draw the boundary across physical and logical infrastructure

Make explicit which layers are in scope: facilities and power, network and hypervisors, host operating systems, and the management plane. Where you offer managed and unmanaged tiers, be clear about which controls you operate versus what the customer runs, so reviewers understand the division of responsibility.

Availability engineering as evidenced, not asserted

Because Availability is the criterion customers care about most, auditors expect tested redundancy, capacity monitoring, backup verification, and a disaster-recovery plan that has actually been exercised with recovery objectives. An untested DR document is a common finding that undermines a hosting provider's central promise.

Tenant isolation and secure media disposal on shared infrastructure

On shared hosts and storage, document how one customer's compute, network, and data are isolated from another's, and how drives and media are securely wiped or destroyed on decommission. Multi-tenant isolation and data remanence are the questions reviewers raise most about shared hosting.

What a SOC 2 audit costs for hosting providers

These are first-party published rates from accredited firms on the AuditNex network — actual prices, not survey estimates. Data as of 2026-07-26.

SOC 2 Type 1 — network rates
$1,500–$5,000
Published range, by company size
SOC 2 Type 2 — network rates
$2,500–$15,000
Published range, by company size

Quote requests priced at network rates: Withheld — 2 samples, below our 5-sample minimum.

Honest data note: the figures above are network-wide — they cover every industry we serve, not Hosting Providers specifically. We do not yet have enough Hosting Providers engagements to publish industry-segmented medians under our 5-sample minimum, and we won’t imply otherwise. What actually moves your price is scope (report type, company size, number of elective criteria), not your industry label. How we use pricing data · Full pricing report

Estimate your SOC 2 cost →

Frameworks hosting providers pair with SOC 2

SOC 2 is rarely the only requirement in this category. These are the frameworks most often pursued alongside it — and overlapping evidence you can reuse if you plan both from the start:

FrameworkWhy it comes up alongside SOC 2
ISO 27001Comes up with international customers and larger enterprises that ask for certification rather than attestation. The control overlap with SOC 2 is substantial, so both engagements can share one evidence base.
Penetration testingCustomer questionnaires expect a recent independent test of the hosting platform, its management plane, and tenant isolation. Scheduling it inside the SOC 2 window lets one test satisfy several reviewers.

Finding an auditor who knows Hosting Providers

Straight answer: no firm in our directory has a confirmed Hosting Providers industry focus on record yet. That reflects our verification data — not the market. Industry tags only appear on a profile after the firm discloses them or public records confirm them; we never guess. Until then, the strongest starting points are the ranked list below (verification status and profile transparency first) and asking each firm directly about Hosting Providers references when you request quotes.

Best SOC 2 auditors for SaaS companies ›  ·  All auditor profiles ›  ·  How we verify auditors ›

SOC 2 for Hosting Providers: common questions

Should hosting providers include the Availability criterion?

In almost all cases, yes. Customers buy hosting specifically for uptime, so a report that omits Availability leaves out the thing they most want assurance on. Including it adds controls for redundancy, capacity, monitoring, backups, and disaster recovery, and lets your report speak directly to the SLAs your contracts promise. Most serious hosting providers scope Security and Availability at minimum.

How do we handle data centers we don't own in our SOC 2?

You use the carve-out method: the colocation or cloud provider is treated as a subservice organization, and you rely on their SOC report for the physical and environmental controls you don't operate. Your own report then covers the logical infrastructure and services you do control. Gather the facility provider's current report before your observation window, because your auditor will expect to see it.

What's the difference in scope between managed and unmanaged hosting?

With managed hosting you operate more of the stack — patching, backups, monitoring, sometimes the application layer — so more controls fall inside your report. With unmanaged hosting the customer runs the operating system and applications, so your scope narrows to the infrastructure and management plane. Make the tier explicit in the system description and use complementary user-entity controls to describe the customer's responsibilities.

How do reviewers evaluate tenant isolation on shared hosting?

They look for evidence that one customer's compute, network, and stored data cannot be reached by another, whether through hypervisor isolation, network segmentation, or account boundaries. They also ask about data remanence — how drives and media are securely wiped or destroyed when hardware is decommissioned. Documenting and testing these controls addresses the main worry buyers have about shared infrastructure.

Get SOC 2 quotes scoped for Hosting Providers

Answer five questions once — we’ll show accredited auditors that fit your scope, with transparent pricing and no sales calls. Scope it the way this guide describes: report type, criteria mix, and timeline are what drive your quotes.

Start a quote →