Cyso achieves SOC 2 Type 2 attestation: what does that mean for you?
By Cyso Cloud on
Last updated on
On 20 February 2026, Cyso officially achieved SOC 2 Type 2 attestation. This is a milestone that fits who we are and what we have been working towards for years: a reliable, independent IT partner that takes the security and privacy of customer data seriously. But what does this attestation actually involve, and why should it matter to you?

What is SOC 2 Type 2?
SOC 2 stands for Service Organization Control 2. It is an audit standard specifically designed for organisations that process, store or manage data on behalf of others.
The distinction between Type 1 and Type 2 matters. A Type 1 report assesses whether the right security measures exist on paper at a specific point in time. Type 2 goes further: an independent auditor confirms that those measures have actually and demonstrably operated effectively over a period of at least six months. It is not about what you intend to do, but proof of what you have actually done.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 is a snapshot. An auditor checks whether the design of your security processes is sound. Type 2 is proof of execution over several months: the auditor tracks how those processes operate over a longer period and verifies that they have been carried out consistently and effectively. That makes Type 2 considerably harder to achieve, and considerably more valuable as evidence for customers and partners.
Type 2 requires continuous monitoring, structured documentation, demonstrable incident response, periodic risk assessments and staff training. It is not a one-off exercise, but living proof of how an organisation operates on a daily basis.
Which criteria are assessed in a SOC 2 Type 2 audit?
The audit is assessed against the five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
Security is the only mandatory criterion and forms the core of every SOC 2 assessment. It covers access management, network segmentation, encryption, monitoring and security incident management.
Availability looks at whether systems and services are available in line with the agreements set out in service level agreements. Think uptime, recovery plans and capacity management.
Processing integrity concerns whether data is processed accurately, on time and in full, without errors or unauthorised changes.
Confidentiality assesses whether sensitive information is accessible only to authorised parties and is not shared unintentionally.
Privacy covers how personal data is collected, used, retained and deleted, in line with privacy regulations such as the GDPR.
Not all five criteria need to be included in every audit. An organisation chooses, together with the auditor, which criteria are relevant to the services it provides. Security is always mandatory; the other four are determined based on scope and service delivery.
Why is SOC 2 Type 2 important for organisations that outsource data?
When an organisation outsources its IT infrastructure, data or applications to an external party, it effectively hands over part of its security responsibility. The question then becomes: how do you know that party is handling that responsibility properly?
A SOC 2 Type 2 attestation provides a concrete, externally verified answer to that question. An independent auditor has established that the service provider's security measures not only exist, but actually work. It is a formal assurance report, drawn up by a certified accountant or audit firm.
For compliance officers, procurement departments and IT managers, this report is a practical tool. It often replaces lengthy questionnaires or in-house supplier audits, and it simplifies demonstrating due diligence to regulators, boards or customers.
For which sectors and organisations is SOC 2 Type 2 relevant?
SOC 2 Type 2 is relevant for any organisation that processes sensitive data, or has it processed by an external party. In practice, it plays a significant role in sectors such as financial services, healthcare, education, government and SaaS. But any scale-up or enterprise with customers that have strict compliance requirements also benefits from being able to show that its suppliers hold this kind of attestation.
Specifically, there are three groups for whom the attestation is directly relevant:
Compliance officers and legal teams use the report to establish whether a supplier meets the requirements arising from legislation, contractual obligations or sector-specific standards.
IT managers and architects can consult the report to assess whether a supplier's technical and operational controls align with their own security requirements.
Procurement teams and management use it as an objective selection criterion when evaluating proposals or carrying out vendor risk management.
How does SOC 2 Type 2 compare to ISO 27001 and NEN 7510?
SOC 2 Type 2 and ISO 27001 overlap in several areas, but they are not the same. ISO 27001 is a management system standard focused on setting up an information security management system. SOC 2 Type 2 is an assurance report focused on the demonstrable operation of controls over a period of time.
Put simply: ISO looks at how the system is built from the inside; SOC 2 Type 2 looks from the outside at whether the system genuinely works well. Together, they show that we have information security in order not just on paper, but in practice too.
In practice, the two reinforce one another. Organisations with a solid ISO 27001 foundation are well prepared for a SOC 2 Type 2 audit. NEN 7510, the Dutch standard for information security in healthcare, has comparable requirements around confidentiality and availability.
Alongside its SOC 2 Type 2 attestation, Cyso also holds ISO 27001 and NEN 7510 certification. For customers in regulated sectors, that combination provides the strongest possible basis for compliance.
View all Cyso's attestations and certifications
How long is a SOC 2 Type 2 attestation valid?
A SOC 2 Type 2 report covers a completed period, typically six to twelve months. To keep the attestation current, a re-audit takes place every year. The report does not have unlimited validity: in practice, a report more than a year old is considered outdated.
This means that a supplier wishing to renew its SOC 2 Type 2 attestation each year must keep its security processes structurally in order. A one-off effort is not enough.
What does Cyso's SOC 2 Type 2 attestation mean for you in practice?
Cyso achieved the attestation on 20 February 2026, following an audit period during which our processes and controls were thoroughly examined by an independent auditor.
For existing customers, this means you have formal, externally verified evidence that the security of your environment at Cyso meets international standards. That makes your own internal and external audits easier.
Looking for an IT partner where security, availability and compliance are not an afterthought but the starting point? We would be glad to think through with you what that means for your specific situation.


