
Short answer: No law requires SOC 2 in any industry. It is buyer driven. In our experience, the industries that most often ask vendors for a SOC 2 report are B2B SaaS, healthcare, financial services and fintech, insurance, HR and payroll, legal, EdTech, data centers and managed service providers, and AI vendors handling customer data.
Related guides:
Key takeaways
- SOC 2 is not a legal mandate. It is an attestation report that a CPA firm issues. Your customers' procurement and security teams decide whether they need it.
- The trigger is your buyer, not your sector label. If you store, process or connect to a customer's sensitive data, expect the question regardless of what industry you call yourself.
- Regulated buyers pass their duties down to you. Laws such as HIPAA, the GLBA Safeguards Rule and state insurance data security laws make your customers oversee their vendors, and a SOC 2 report is a common way they do it.
- Some buyers want something else as well or instead. Healthcare may add HIPAA or HITRUST, payments brings PCI DSS, federal work brings FedRAMP or CMMC, and international buyers often prefer ISO 27001.
- Check your pipeline before you start. If deals are not stalling on security reviews, SOC 2 may not be your first move.
Is SOC 2 required by law?
No. SOC 2 is a voluntary examination performed by an independent CPA firm under AICPA standards, and no federal statute names it as a requirement.
The AICPA describes its SOC suite as assurance reports that give users information needed to assess and address the risks of outsourcing services. Its SOC 2 guide covers controls at a service organization relevant to security, availability, processing integrity, confidentiality or privacy. Those five areas are the Trust Services Criteria (TSCs).
So who needs SOC 2 compliance? Any service organization whose customers ask for it. The requirement shows up in a security questionnaire, a vendor onboarding checklist or a contract clause, not in a statute.
Which industries need SOC 2? An industry-by-industry view
The industries that ask most often are the ones that trust vendors with sensitive data or critical operations. The table below reflects common practice in our experience. Your specific buyers may differ, so treat it as a starting map, not a rulebook.
| Industry (your buyers) | Why buyers ask | TSCs that commonly matter | Frameworks buyers may ask for alongside or instead |
|---|---|---|---|
| SaaS and B2B tech | Standard step in enterprise security review | Security, Availability, Confidentiality | ISO 27001 for international buyers |
| Healthcare and HealthTech | Vendors often handle protected health information (PHI) | Security, Confidentiality, Privacy | HIPAA (with a BAA), HITRUST |
| Financial services and fintech | Customers must oversee service providers | Security, Availability, Processing Integrity, Confidentiality | GLBA Safeguards Rule evidence, PCI DSS, ISO 27001 |
| Insurance | Carriers and agencies oversee third-party providers | Security, Confidentiality, Privacy | State insurance data security laws, ISO 27001 |
| HR and payroll | Employee personal and pay data, payroll accuracy | Security, Processing Integrity, Confidentiality, Privacy | ISO 27001, GDPR evidence for EU staff data |
| Legal | Privileged and confidential client matters | Security, Confidentiality | ISO 27001, client-specific security addenda |
| Education and EdTech | Student records and school data agreements | Security, Privacy, Confidentiality | FERPA contract terms, state student privacy agreements |
| Government contractors | Federal and defense data handling | Security, Availability | FedRAMP for cloud services, CMMC for defense contracts |
| Data centers and MSPs | Customers inherit your controls into their own audits | Security, Availability | ISO 27001, PCI DSS for payment environments |
| AI vendors | Customer data used in prompts, training or outputs | Security, Confidentiality, Privacy, Processing Integrity | ISO/IEC 42001, ISO 27001 |
Notice the pattern: Security appears in every row because the security category, known as the common criteria, is the baseline of every SOC 2 report. The other categories are chosen based on what you promise customers.
Why do buyers in each industry ask for SOC 2?
Buyers ask because they remain accountable for data they hand to you, and a SOC 2 report lets them check your controls without auditing you themselves.
SaaS and B2B tech. Security reviews are routine in mid-market and enterprise sales. A SOC 2 Type 2 report answers a large share of the questionnaire in one document, which is why it is often the first framework growing SaaS companies pursue. Our guide to SOC 2 for startups covers timing for early-stage teams.
Healthcare and HealthTech. Under HIPAA, a covered entity must get satisfactory assurances, in a business associate agreement, that a business associate will appropriately safeguard PHI. SOC 2 is not a HIPAA certification, but health systems commonly use it as evidence during vendor review. Some larger health systems and payers prefer HITRUST. For detail, see SOC 2 for healthcare.
Financial services and fintech. The FTC's Safeguards Rule, which implements part of the GLBA for non-bank financial institutions, tells covered businesses to select service providers that can maintain appropriate safeguards, put security expectations in contracts and periodically reassess them. If you touch card data, PCI DSS applies to entities that store, process or transmit cardholder data, and SOC 2 does not replace it.
Insurance. The NAIC Insurance Data Security Model Law includes oversight of third-party service providers, and the NAIC reported that 28 jurisdictions had adopted it as of August 2025. Carriers and agencies in those states need a way to assess vendors, and in our experience a SOC 2 report is a common one.
HR and payroll. Payroll and HR platforms hold Social Security numbers, bank details and compensation data for every employee of a customer. Buyers usually care about Processing Integrity as well as Security, because a wrong payroll run is a business failure, not just a data incident.
Legal. Law firms and corporate legal teams treat client confidentiality as a professional obligation. Vendors for e-discovery, document management and contract tools often see SOC 2 or ISO 27001 requests, plus client-specific outside counsel security requirements.
Education and EdTech. Under FERPA, a vendor can receive education records as a "school official" only if, among other conditions, it performs a service the school would otherwise use employees for and is under the school's direct control regarding the use and maintenance of those records. Districts and universities write that control into contracts and security questionnaires, and larger institutions often ask for SOC 2 or a comparable report.
Government contractors. For federal cloud work, FedRAMP is the relevant program. GSA describes it as a standardized approach to security and risk assessment for cloud products and services. For defense work, the DoD CIO explains that CMMC levels apply as a contract requirement to contractors and subcontractors handling FCI or CUI; its implementation phases have changed during 2026, so check the current status as of October 2026. SOC 2 helps with commercial and state buyers but does not substitute for either.
Data centers and managed service providers. Your customers often rely on your controls in their own audits. Their auditors will want your SOC 2 report to evaluate the controls they inherit from you, so colocation, hosting and MSP buyers ask early and expect Availability in scope.
AI vendors. Buyers want to know whether their data is used for training, how prompts and outputs are stored, and who can access them. SOC 2 covers the security foundation. Some buyers also ask about ISO/IEC 42001, which specifies requirements for an AI management system.
Which Trust Services Criteria should you include?
Include Security in every case, then add only the categories that match commitments you actually make to customers. Adding criteria you cannot support creates audit findings and extra work.
- Security (required). Access control, change management, monitoring, incident response and vendor management.
- Availability. Add it if you publish uptime commitments or SLAs, or if customers depend on you for operations. Common for infrastructure, MSPs and payroll.
- Confidentiality. Add it if you handle customer business secrets, legal matters, financial data or source code under contract.
- Processing Integrity. Add it if customers rely on your system to compute or transact correctly, such as payments, payroll, claims or model outputs.
- Privacy. Add it if you collect personal information directly from individuals and make privacy commitments to them. Many B2B vendors cover personal data under Confidentiality instead.
Read your top customers' contracts and questionnaires and map each request to a category.
Signals you need SOC 2 now: a checklist
If two or more of these apply, SOC 2 is probably worth starting this quarter.
- A prospect has asked for your SOC 2 report, by name, in the last few months.
- Deals are stalling in security review or procurement.
- You keep answering long security questionnaires that cover the same ground.
- You are moving from SMB customers to mid-market or enterprise.
- Your customers are in healthcare, financial services, insurance, HR, legal or education.
- You store, process or have access to customer data in production.
- A partner, marketplace or reseller program requires an independent security report.
- Your customers' own auditors ask about controls they inherit from you.
When is SOC 2 not the right first step?
SOC 2 is the wrong first step when your buyers need a different framework, when you have no buyer demand yet, or when you do not handle customer data. Common cases:
- You sell mainly outside the US. International buyers frequently prefer ISO 27001, which specifies requirements for an information security management system. Compare them in SOC 2 vs ISO 27001.
- You sell cloud services to federal agencies. FedRAMP is the path agencies use, and a SOC 2 report will not replace it.
- You handle card data directly. PCI DSS comes first for the cardholder data environment.
- You are pre-revenue or pre-product. Build good security habits and a basic policy set, but wait for a real customer request before paying for an audit.
- You do not touch customer data. Some consumer apps and internal tools never face vendor review.
We cover more of these cases in 5 reasons your company may not need SOC 2. Whatever you choose, build controls once and map them to each framework, so a later SOC 2 is a mapping exercise rather than a restart.
How SecureSlate helps
SecureSlate gives SMB, SaaS and HealthTech teams one control library mapped across built-in frameworks including SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, ISO 42001, CMMC and FedRAMP, so the industry-specific requests in the table above build on the same controls. Custom frameworks and controls cover buyer-specific requirements such as state student privacy terms.
Agentless, read-only cloud integrations and a device agent for endpoint checks such as disk encryption collect evidence. Access reviews, vendor risk management and risk management cover recurring SOC 2 activities. Security questionnaire automation drafts answers from your own documents for review and export, and a trust center shares your certifications, policies and subprocessors with public or restricted access. When you are ready, audit management gives your auditor a workspace and an evidence tracker.
Start your free SecureSlate trial
FAQ
Who needs SOC 2 compliance?
Any service organization whose customers ask for a SOC 2 report. In practice that is usually B2B companies that store, process or access customer data, especially those selling to healthcare, financial services, insurance, HR, legal and education buyers.
Is SOC 2 mandatory for healthcare or financial companies?
No law names SOC 2 as mandatory. HIPAA and the GLBA Safeguards Rule do require regulated companies to oversee their vendors, so healthcare and financial buyers commonly ask for a SOC 2 report as part of that oversight.
Does SOC 2 replace HIPAA, PCI DSS or FedRAMP?
No. Each has its own scope and requirements. A SOC 2 control set overlaps with them and can be reused as evidence, but you still need to meet each framework's specific obligations.
Which industries are least likely to ask for SOC 2?
In our experience, purely consumer businesses, local service businesses and companies that never access customer data are least likely to face SOC 2 requests, because no business customer is performing vendor due diligence on them.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds