Overview
The AICPA's Trust Services Criteria, an attestation for service organizations that handle customer data.
Lexradar tracks every change to SOC 2 and surfaces it in your compliance feed, mapped to the specific clauses your team is responsible for.
Who uses SOC 2
SOC 2 is the de jure or de facto standard for information security, privacy, and operational resilience in the following contexts:
- Regulated financial services firms (banks, insurers, payment service providers).
- SaaS companies selling to enterprise and public-sector buyers.
- Healthcare organisations handling personal health information.
- Critical infrastructure operators and their supply chain.
- Any organisation subject to overlapping regional and sectoral requirements.
How Lexradar helps
A team using SOC 2 inside Lexradar gets:
- A change feed filtered to SOC 2 clauses — every regulatory update is mapped to the specific control it affects.
- AI-drafted policy responses — the policy drafting service generates a first-draft response to a change, with citations to the source material and the relevant clause.
- Cross-framework comparison — see how a change in SOC 2 ripples into ISO 27001, NIST CSF, SOC 2, and the EU AI Act, where applicable.
- Department Impact Matrix — see which teams and processes are affected by a change before you brief them.
- Audit log + CSV export — every action a team member takes on a SOC 2-related control is recorded, exportable, and append-only.
Official sources
This page is a plain-English overview. The binding text and authoritative guidance are issued by the body named on the page header. Always refer to the official source for legal questions.
Found an error or an outdated link? Email Admin@lexradar.co.