HR Software

What is SOC 2 and why do HR software buyers ask about it?

SOC 2 is an independent audit report on how a service provider handles security, and optionally availability, confidentiality, processing integrity and privacy. Buyers ask for it because HR systems hold sensitive personal data. A Type II report covers how controls performed over a period, which is more informative than Type I's point-in-time design assessment.

What does a SOC 2 report actually cover?

An independent auditor's examination of a provider's controls against defined trust services criteria. Security is always included; availability, confidentiality, processing integrity and privacy are optional additions, so two reports described the same way can cover different ground. Type I assesses whether controls are suitably designed at a single date. Type II tests whether they operated effectively across a period, usually six to twelve months, which is the version worth asking for. The report includes the auditor's opinion, a description of the system, the controls tested and, importantly, any exceptions found. Most buyers read the opinion page and stop. The exceptions section and the complementary user entity controls, which list what you are responsible for, are where the useful information sits.

How much weight should it carry in a decision?

Treat it as evidence of process maturity rather than proof of safety. A current Type II report tells you the vendor has a security programme that survives external examination, which is meaningful and filters out a lot of risk. It does not tell you where your candidate data will be stored, which subprocessors handle it, how deletion works in the product, or whether the permission model fits your team. Those remain separate questions. It is also worth noting that absence of a report does not automatically mean weak security, particularly for smaller vendors where the cost of certification is significant relative to their size. Ask what they have instead: penetration testing results, an equivalent certification, or a documented security programme you can review.

How do you review a report you have been given?

Check five things. The period covered and whether it is current, since reports age and a lapsed one tells you about the past. Which trust services criteria are in scope. The auditor's opinion, and whether it is qualified. The exceptions listed, what they concerned and what remediation is described. And the complementary user entity controls, which specify what the vendor assumes you will do, such as managing user access, enforcing multi-factor authentication and configuring permissions correctly. That last section frequently surprises buyers, because it makes clear that a portion of the security posture is your responsibility regardless of the vendor's certification. Route the review through whoever owns security at your organisation, and keep the report with your evaluation records rather than treating it as a formality.

What else should sit alongside it?

A data processing agreement, a current subprocessor list, documentation of where data is stored, retention and deletion capability in the product, and the practical access controls your team will rely on daily: single sign-on, role-based permissions, and audit logging of who viewed which candidate. Together these give a picture that no single certificate provides. It is also worth asking about incident history and how the vendor communicates during an incident, since that behaviour is not covered by an audit opinion. Combine the answers with your functional evaluation rather than running security as a separate late-stage gate, because a security finding after selection is the most common cause of a decision unwinding. Start the review when you start looking at [applicant tracking software](/ats), not after you have chosen.

Want Pitch N Hire to handle this for your team?

Related glossary terms

Next step

FAQ

Frequently asked questions

Is SOC 2 the same as ISO 27001? +
No. ISO 27001 certifies an information security management system against an international standard, while SOC 2 is an auditor's report on controls against trust services criteria. Both are credible signals and they overlap substantially in practice. Which one a vendor holds often reflects the markets they sell into rather than a difference in security quality.
Should we reject a vendor without SOC 2? +
Not automatically, particularly for smaller suppliers where certification cost is disproportionate. Ask what alternative evidence exists: independent penetration testing, an equivalent certification, or a documented programme with named controls. Then weigh the answer against the sensitivity of the data and your own regulatory obligations, which may make certification non-negotiable regardless.
How do we get a copy of the report? +
Ask the vendor during evaluation. Most provide it under a confidentiality agreement rather than publishing it, which is normal. If a vendor claims certification but will not share the report under any terms, treat the claim as unverified, since the summary on a website is not the same as the auditor's findings.
Does certification cover the vendor's subprocessors? +
Usually only where those subprocessors fall inside the audit scope, which varies. Ask specifically whether the parsing engine, email delivery, video hosting and any AI provider are covered, or whether they carry their own certifications. This matters because your candidate data often passes through several companies, not just the one you contracted with.
Built for recruiters & hiring teams

See how much faster your team could hire

Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo