Hacker News new | ask | show | jobs
by max-ibel 975 days ago
Great question. I'd be also interested in good auditor firms. That's really what SOC is - sign off by auditors on criteria. SOC-1 is for an initial snapshot, SOC-2 for a 1 year interval or so, proving the controls work.