←back to thread

233 points gmays | 1 comments | | HN request time: 0s | source
Show context
ranger_danger ◴[] No.44362456[source]
> We got tired of endless security questionnaires, so we got SOC 2 certified to make things smoother for everyone.

Can someone explain what they meant by this? Questionnaires by who, and why?

replies(5): >>44362472 #>>44362477 #>>44362480 #>>44362493 #>>44363749 #
1. Analemma_ ◴[] No.44362493[source]
If you’re not SOC2 certified, a lot of orgs (by policy or by law) have to ask you tons of questions about your security situation to verify that you’re “as good as” SOC2 before they can do business with you.

Strictly speaking it’s better than a hard-and-fast requirement to be certified— at least you have some choice— but as was the case here it tends to be so onerous and repetitive that people tend to just get the certification.