SOC 2 Audits for Hosting Providers
Companies running their websites, applications, and managed servers on your infrastructure depend on you to stay up and keep their data isolated — so their security and procurement teams expect a SOC 2 before they migrate. Here is how hosting providers scope the audit — criteria, the data-center question, controls, and cost.
Why hosting providers get asked for SOC 2
Hosting providers are foundational vendors: if you run web and application hosting, managed servers, or colocation-adjacent SaaS, your customers' uptime is your uptime and your customers' data isolation is your responsibility. Because you sit beneath everything they serve, their vendor-risk teams and their own auditors ask for a SOC 2 as a matter of course, and Availability tends to be a headline concern rather than an afterthought — an outage on your platform is directly visible to their users.
The evaluation is unusually infrastructure-heavy. Reviewers want to understand physical security and environmental controls of the facilities, logical isolation between tenants on shared hosts, patching and hardening of the underlying platform, and how you handle backups, capacity, and disaster recovery. A recurring question is whether the data centers themselves are inside your report or carved out to a colocation or cloud provider — and how you evidence the controls you don't physically own.
Trust Services Criteria focus for Hosting Providers
Security (the Common Criteria) is mandatory in every SOC 2 report. The other four criteria are elective — you scope them in based on what your customers actually rely on. Here is how hosting providers typically scope them, and why:
| Criterion | Typical scope | Why it matters in Hosting Providers |
|---|---|---|
| Security | Always in scope | Mandatory in every SOC 2. For hosting, expect scrutiny on tenant isolation across shared servers, hardening and patching of the underlying platform, and access controls over hypervisors, management consoles, and customer data stores. |
| Availability | Always in scope | Effectively core for this category: customers buy hosting for uptime, so reviewers expect SLAs backed by tested redundancy, capacity planning, monitored failover, and evidence of a real disaster-recovery exercise. |
| Confidentiality | Common | You store customer applications, databases, and backups. Reviewers look for classification, encryption at rest and in transit, and retention and secure-disposal controls over the data hosted on your platform. |
| Processing Integrity | Sometimes | Scoped in when customers rely on managed services such as backups or migrations completing accurately and completely. Pure infrastructure hosting often treats this as reliability and leaves the criterion out. |
| Privacy | Rarely included | Uncommon for infrastructure providers, since you host data on customers' behalf rather than determining its use. Most hosting providers address data protection through Security and Confidentiality controls instead. |
Each elective criterion adds controls and evidence — and cost. Scope what your customers demand in security reviews, not everything at once.
Scoping decisions specific to Hosting Providers
These are the Hosting Providers-specific calls that shape your system description, control list, and ultimately your audit price. Settle them before you request quotes — firms price scope, not industry labels.
Decide the carve-out vs inclusive method for data centers
If you run in colocation or on a cloud provider, you typically carve out the facility as a subservice organization and rely on its SOC report for physical and environmental controls. If you own the data centers, an inclusive approach puts those controls in your own report. Settle this first — it defines what your auditor tests directly versus what they rely on from others.
Draw the boundary across physical and logical infrastructure
Make explicit which layers are in scope: facilities and power, network and hypervisors, host operating systems, and the management plane. Where you offer managed and unmanaged tiers, be clear about which controls you operate versus what the customer runs, so reviewers understand the division of responsibility.
Availability engineering as evidenced, not asserted
Because Availability is the criterion customers care about most, auditors expect tested redundancy, capacity monitoring, backup verification, and a disaster-recovery plan that has actually been exercised with recovery objectives. An untested DR document is a common finding that undermines a hosting provider's central promise.
Tenant isolation and secure media disposal on shared infrastructure
On shared hosts and storage, document how one customer's compute, network, and data are isolated from another's, and how drives and media are securely wiped or destroyed on decommission. Multi-tenant isolation and data remanence are the questions reviewers raise most about shared hosting.
What a SOC 2 audit costs for hosting providers
These are first-party published rates from accredited firms on the AuditNex network — actual prices, not survey estimates. Data as of 2026-07-26.
Quote requests priced at network rates: Withheld — 2 samples, below our 5-sample minimum.
Frameworks hosting providers pair with SOC 2
SOC 2 is rarely the only requirement in this category. These are the frameworks most often pursued alongside it — and overlapping evidence you can reuse if you plan both from the start:
| Framework | Why it comes up alongside SOC 2 |
|---|---|
| ISO 27001 | Comes up with international customers and larger enterprises that ask for certification rather than attestation. The control overlap with SOC 2 is substantial, so both engagements can share one evidence base. |
| Penetration testing | Customer questionnaires expect a recent independent test of the hosting platform, its management plane, and tenant isolation. Scheduling it inside the SOC 2 window lets one test satisfy several reviewers. |
Finding an auditor who knows Hosting Providers
Best SOC 2 auditors for SaaS companies › · All auditor profiles › · How we verify auditors ›
SOC 2 for Hosting Providers: common questions
Should hosting providers include the Availability criterion?
In almost all cases, yes. Customers buy hosting specifically for uptime, so a report that omits Availability leaves out the thing they most want assurance on. Including it adds controls for redundancy, capacity, monitoring, backups, and disaster recovery, and lets your report speak directly to the SLAs your contracts promise. Most serious hosting providers scope Security and Availability at minimum.
How do we handle data centers we don't own in our SOC 2?
You use the carve-out method: the colocation or cloud provider is treated as a subservice organization, and you rely on their SOC report for the physical and environmental controls you don't operate. Your own report then covers the logical infrastructure and services you do control. Gather the facility provider's current report before your observation window, because your auditor will expect to see it.
What's the difference in scope between managed and unmanaged hosting?
With managed hosting you operate more of the stack — patching, backups, monitoring, sometimes the application layer — so more controls fall inside your report. With unmanaged hosting the customer runs the operating system and applications, so your scope narrows to the infrastructure and management plane. Make the tier explicit in the system description and use complementary user-entity controls to describe the customer's responsibilities.
How do reviewers evaluate tenant isolation on shared hosting?
They look for evidence that one customer's compute, network, and stored data cannot be reached by another, whether through hypervisor isolation, network segmentation, or account boundaries. They also ask about data remanence — how drives and media are securely wiped or destroyed when hardware is decommissioned. Documenting and testing these controls addresses the main worry buyers have about shared infrastructure.
Get SOC 2 quotes scoped for Hosting Providers
Answer five questions once — we’ll show accredited auditors that fit your scope, with transparent pricing and no sales calls. Scope it the way this guide describes: report type, criteria mix, and timeline are what drive your quotes.
Start a quote →