SOC 2 is an independent audit report on how a service provider handles security, and optionally availability, confidentiality, processing integrity and privacy. Buyers ask for it because HR systems hold sensitive personal data. A Type II report covers how controls performed over a period, which is more informative than Type I's point-in-time design assessment.
An independent auditor's examination of a provider's controls against defined trust services criteria. Security is always included; availability, confidentiality, processing integrity and privacy are optional additions, so two reports described the same way can cover different ground. Type I assesses whether controls are suitably designed at a single date. Type II tests whether they operated effectively across a period, usually six to twelve months, which is the version worth asking for. The report includes the auditor's opinion, a description of the system, the controls tested and, importantly, any exceptions found. Most buyers read the opinion page and stop. The exceptions section and the complementary user entity controls, which list what you are responsible for, are where the useful information sits.
Treat it as evidence of process maturity rather than proof of safety. A current Type II report tells you the vendor has a security programme that survives external examination, which is meaningful and filters out a lot of risk. It does not tell you where your candidate data will be stored, which subprocessors handle it, how deletion works in the product, or whether the permission model fits your team. Those remain separate questions. It is also worth noting that absence of a report does not automatically mean weak security, particularly for smaller vendors where the cost of certification is significant relative to their size. Ask what they have instead: penetration testing results, an equivalent certification, or a documented security programme you can review.
Check five things. The period covered and whether it is current, since reports age and a lapsed one tells you about the past. Which trust services criteria are in scope. The auditor's opinion, and whether it is qualified. The exceptions listed, what they concerned and what remediation is described. And the complementary user entity controls, which specify what the vendor assumes you will do, such as managing user access, enforcing multi-factor authentication and configuring permissions correctly. That last section frequently surprises buyers, because it makes clear that a portion of the security posture is your responsibility regardless of the vendor's certification. Route the review through whoever owns security at your organisation, and keep the report with your evaluation records rather than treating it as a formality.
A data processing agreement, a current subprocessor list, documentation of where data is stored, retention and deletion capability in the product, and the practical access controls your team will rely on daily: single sign-on, role-based permissions, and audit logging of who viewed which candidate. Together these give a picture that no single certificate provides. It is also worth asking about incident history and how the vendor communicates during an incident, since that behaviour is not covered by an audit opinion. Combine the answers with your functional evaluation rather than running security as a separate late-stage gate, because a security finding after selection is the most common cause of a decision unwinding. Start the review when you start looking at [applicant tracking software](/ats), not after you have chosen.
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert