A prospect's legal team asks whether your SaaS platform is SOC 2 Type II certified. Why does Type II matter more than Type I to enterprise buyers?
-
A
Type II covers more product features than Type I
-
B
Type II certifies that controls were operating effectively over a period of time (usually 6-12 months), not just that they exist at a single point in time
-
C
Type II is required by law; Type I is voluntary
-
D
Type II includes penetration test results while Type I does not