Skip to main content
New: Essentials: Security — security products for small teams.Learn more →
Resource Library

Many frameworks. One managed approach.

A reference guide to the major cybersecurity and compliance standards ComplianceXO serves. Click a framework to read the key requirements, enforcement notes, and our commentary.

Trust service criteria

SOC 2

SOC 2 governs how service organizations manage and protect customer data across five trust service criteria: security, availability, processing integrity, confidentiality, and privacy.

Key requirements · 5 items
  1. 1Security controls and continuous monitoring
  2. 2Incident response procedures and tabletop exercises
  3. 3Access controls and multi-factor authentication
  4. 4Vendor management and third-party risk
  5. 5Regular risk assessments and control testing