Last updated: July 26, 2026
SOC 2 by Industry

SOC 2, scoped for your industry

The SOC 2 framework is the same for everyone — but what auditors scrutinize, which Trust Services Criteria you scope in, and which frameworks you pair it with all depend on what your product does and who buys it. 50 category-specific guides, one per software vertical.

Why industry context changes your audit

Every SOC 2 covers the mandatory Security criteria. The real scoping decisions — whether to add Availability, Confidentiality, Processing Integrity, or Privacy, which systems land in the audit boundary, and what evidence your customers expect — track your category. A payments platform gets asked different questions in security reviews than an edtech vendor. Each guide below covers the criteria mix, category-specific scoping calls, framework pairings, and honest first-party cost data for that vertical.

All 50 industry guides

Financial services software

Healthcare & life sciences

Data, AI & infrastructure

Public sector & regulated industries

Commerce & consumer platforms

Operations, hardware & field

Go-to-market & workforce software

Skip the research — get matched

Answer five questions and compare accredited auditors that fit your scope, with transparent pricing and no sales calls.

Start a quote →