BlogData RoomsSOC 2 Compliant Data Room 2026: Type I vs II and 9 Vendor Questions

SOC 2 Compliant Data Room 2026: Type I vs II and 9 Vendor Questions

15 min read
Marc Seitz

Marc Seitz

A SOC 2 compliant data room is a virtual data room whose operator holds a current SOC 2 report from an independent CPA firm, attesting that its controls over customer data meet the AICPA Trust Services Criteria. The report is the evidence. A claim of compliance on a marketing page is not.

Quick recap

  • SOC 2 is an attestation standard from the American Institute of Certified Public Accountants, not a certification body, so no organisation is ever certified in SOC 2 the way it is certified in ISO 27001.
  • A SOC 2 Type I report tests whether controls were designed correctly at a single point in time; a Type II report tests whether they operated effectively across a period, usually 6 or 12 months.
  • Enterprise procurement asks for Type II. A Type I is normally a staging post while a vendor accumulates the observation window for its first Type II.
  • There are five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Only security, the Common Criteria, is mandatory in every SOC 2 audit.
  • For a data room, the criteria that matter most are security, confidentiality, and availability. Processing integrity is rarely material because a VDR does not compute anything.
  • A SOC 2 report is scoped, so it may cover only part of a vendor's platform. Read the system description before accepting the report.
  • Type I typically takes a few weeks to a few months to issue; Type II typically takes 6 to 12 months from kickoff to an issued report.
  • Reports carry an audit period with an end date. Anything past that end date needs a bridge letter from the vendor covering the gap.
  • Papermark is SOC 2 Type II compliant, with the audit covering the security, availability, and confidentiality criteria; on the data room ladder, SOC 2 Type II sits on the Data Rooms Plus plan at €249/month.

Most buyers of a SOC 2 compliant data room never read the report they asked for. They tick a box in a vendor questionnaire, file the PDF, and move on. That is a shame, because almost everything that matters about a SOC 2 report is in the parts nobody reads: the scope statement, the audit period, the exceptions, and the complementary controls the report assumes you will run yourself.

This guide covers what SOC 2 is, how Type I and Type II differ, which of the five criteria a data room actually needs, what the report does not tell you, and the nine questions to put to a vendor before you sign.

No credit card required.

1. What a SOC 2 compliant data room actually is

SOC 2 stands for System and Organization Controls 2. It is an auditing framework developed by the AICPA for service organisations that hold or process customer data, and it produces a report written by an independent CPA firm rather than a certificate issued by a standards body. That distinction matters more than it sounds: there is no SOC 2 registry to look a vendor up in, so the only way to verify a claim is to read the report.

Applied to a virtual data room, SOC 2 covers the operator, not your deal. The auditor tests how the vendor manages access to its production systems, how it encrypts data, how it onboards and offboards engineers, how it responds to incidents, how it manages changes to the platform, and how it monitors what is happening. A SOC 2 compliant data room therefore tells you something about the company you are trusting with 600 diligence documents, and nothing at all about whether you have configured the permissions on those documents sensibly.

That is the honest framing to carry into a vendor conversation. A SOC 2 report reduces the risk that the platform itself is the weak link. It does not reduce the risk that someone on your side emails a bidder a link with download enabled. Both risks are real, and only one of them is the vendor's job.

The reason the standard has become a purchasing requirement is procurement mechanics rather than security theory. Once a legal team, a bank, or an enterprise customer has a vendor questionnaire, SOC 2 Type II is question one. Vendors that cannot produce the report get filtered before anyone evaluates the product, which is why a SOC 2 compliant data room is now table stakes at the enterprise end of the market rather than a differentiator.

2. SOC 2 Type I vs Type II: the distinction procurement cares about

The two report types answer different questions, and confusing them is the most common mistake in vendor review.

A Type I report attests to the design of controls at a specific date. The auditor looks at the vendor's control set and forms an opinion on whether, as designed, those controls would meet the relevant criteria. It is a snapshot. It says the vendor has written the right policies and stood up the right systems as of, say, 30 June.

A Type II report attests to the operating effectiveness of those same controls across a defined period, typically 6 or 12 months. The auditor samples evidence across the window: access reviews actually performed, tickets actually raised, backups actually tested, offboarding actually completed within the stated window. It is the difference between a vendor saying it revokes engineer access within 24 hours of departure and an auditor confirming that it did so for each of the eleven people who left during the period.

DimensionSOC 2 Type ISOC 2 Type II
What it testsControl design at one point in timeControl design plus operating effectiveness over a period
Period coveredA single dateTypically 6 or 12 months
Typical time to issueA few weeks to a few months6 to 12 months from kickoff
Evidence sampledPolicies, configurations, system descriptionsTickets, logs, access reviews, incident records across the window
What procurement acceptsSometimes, as an interim with a Type II date committedThe standard requirement
What it proves about a data room vendorThe controls existThe controls were followed

A vendor holding only a Type I is not necessarily a bad choice. Every organisation that has a Type II held a Type I first, because the observation period has to run before it can be audited. What matters is whether the vendor can tell you the date its first Type II period ends and which firm is performing the audit. A vendor that has held a Type I for three years without progressing is a different signal entirely.

3. The five Trust Services Criteria and which ones a data room needs

SOC 2 audits are scoped around five Trust Services Criteria. Only one is compulsory; the other four are included at the vendor's election, usually driven by what its customers ask for.

Security is the Common Criteria and appears in every SOC 2 audit. It covers logical and physical access controls, encryption, network security, change management, incident response, and monitoring. When someone says a vendor is SOC 2 compliant with no further qualification, this is the part they can be sure was tested.

Availability covers whether the system is available for operation as committed: uptime commitments, resilience, capacity planning, backup, and disaster recovery. For a data room this is more material than it first appears. A room that is down during the 48 hours before a bid deadline is a commercial problem, not just an inconvenience.

Confidentiality covers information designated as confidential: how it is classified, who can reach it, how long it is retained, and how it is destroyed. For a virtual data room holding an unsigned purchase agreement and a customer contract schedule, this criterion is the one closest to the product's actual purpose.

Processing integrity covers whether processing is complete, valid, accurate, timely, and authorised. It matters for systems that calculate things. A data room stores and serves documents rather than computing balances, so this criterion is frequently and legitimately left out of scope.

Privacy covers the collection, use, retention, disclosure, and disposal of personal information against the AICPA privacy principles. It overlaps with GDPR without being the same framework, and many vendors address personal data through GDPR-aligned controls and a data processing agreement rather than by adding the privacy criterion to the SOC 2 scope.

CriterionIn scope by default?Why it matters for a data room
SecurityAlways, it is the Common CriteriaAccess control, encryption, and incident response on the platform holding your deal
AvailabilityElectedUptime through a bid deadline or a regulator's filing window
ConfidentialityElectedClassification, access, retention, and destruction of deal documents
Processing integrityElected, rarely relevantA VDR serves documents rather than computing values
PrivacyElectedOften addressed through GDPR controls and a DPA instead

The practical test for a buyer is simple. Ask which criteria the report covers, and if the answer is security only, ask why confidentiality was left out of a product whose entire premise is confidentiality.

Papermark data room security settings showing encryption, access control, and link protection

Platform controls tested by a SOC 2 audit sit underneath the link-level settings a deal team touches every day.

4. What a SOC 2 report does not tell you

A SOC 2 report is a useful document that is routinely over-read. Five things it does not do are worth knowing before you accept one as proof.

It does not cover everything the vendor sells. Reports carry a system description defining which services, environments, and locations were in scope. A vendor with a data room, an e-signature product, and an analytics service may have audited one of the three. Read the description, not the cover page.

It does not run forever. Every Type II report names an audit period with a start and end date. If today is nine months past that end date, the report tells you about a window that closed nine months ago. The standard remedy is a bridge letter, sometimes called a gap letter, in which the vendor asserts that no material changes occurred between the period end and today. Ask for it.

It does not mean there were no findings. Auditors record exceptions where a control did not operate as described, along with management's response. A report with two minor exceptions and a documented remediation is often a better signal than one with none, because it suggests the auditor tested properly. Read the exceptions section.

It does not do your half of the work. Most reports list complementary user entity controls, the things the report assumes the customer is doing. For a data room those typically include managing your own user accounts, setting permissions appropriately, and revoking access when a counterparty drops out of a process. If you do not do them, the vendor's SOC 2 does not save you.

It is not ISO 27001, and it is not GDPR. SOC 2 is an attestation on controls against AICPA criteria. ISO 27001 certifies an information security management system against an international standard. GDPR is law. A vendor can hold a clean SOC 2 Type II and still be the wrong choice for a deal where personal data leaves the EU. Our data room compliance guide covers how the frameworks interact.

5. The 9 questions to ask a data room vendor about SOC 2

Vendor security questionnaires tend to ask whether a supplier is SOC 2 compliant, accept a yes, and stop. These nine questions take a fifteen-minute call and reliably separate a real attestation from a marketing claim.

#QuestionWhat a good answer looks like
1Is your report Type I or Type II?Type II, or Type I with a named date for the first Type II period end
2What audit period does the current report cover?A 6 or 12 month window ending within the last 12 months
3Which Trust Services Criteria are in scope?Security plus confidentiality at minimum, availability for most deal workflows
4Which of your services are in the system description?The data room product specifically, named, not the company in general
5Which CPA firm performed the audit?A named firm you can verify, not an unnamed third party
6Were there exceptions, and how were they remediated?A direct answer with dates, rather than a claim of zero findings
7Can you provide a bridge letter to today's date?Yes, issued on request, covering the period since the report end date
8What complementary user entity controls do you assume?A specific list, usually access management and permission configuration
9How do I get the report, and under what terms?Under NDA, within a few working days, without a sales escalation

Question seven is the one most often skipped and most often revealing. A vendor with a mature compliance function issues bridge letters routinely. A vendor that has never heard the term is telling you something about how many enterprise reviews it has been through.

Question nine is the practical one. A SOC 2 report is a confidential document and no vendor should publish it openly, but the friction involved in obtaining it under NDA is a fair proxy for how the vendor handles security requests generally. Days is normal. Weeks is a warning.

6. Worked scenario: a fintech reviews six data room vendors

Meridian Pay is a hypothetical payments company preparing a Series C raise and a simultaneous acquisition of a smaller competitor. Its security team runs vendor reviews for every system that will hold customer or counterparty data, and the data room is the one the CFO wants signed off fastest, because the raise opens in five weeks.

The team shortlists six data room vendors and asks all six the nine questions above. Two return a current SOC 2 Type II report covering security, availability, and confidentiality, with audit periods ending within the previous eight months and bridge letters issued on request. One returns a Type II whose audit period ended nineteen months earlier and cannot produce a bridge letter, which the security lead treats as a fail rather than a delay. One holds a Type I only, with a stated Type II period ending in four months, which is a plausible answer from a growing vendor but does not clear procurement for a system holding acquisition documents. Two produce no attestation at all and offer a security whitepaper instead.

Meridian Pay vendor review: SOC 2 status across 6 shortlisted data rooms
6vendors reviewed
  • Current Type II, bridge letter available2 · 33%
    Audit period ended within the last 8 months, security plus confidentiality in scope
  • Type II, audit period stale1 · 17%
    Period ended 19 months ago, no bridge letter offered
  • Type I only1 · 17%
    First Type II period ends in 4 months
  • No attestation2 · 33%
    Security whitepaper offered in place of a report

Worked scenario. The distribution reflects what a mid-market security review typically finds when it asks for the report rather than accepting a compliance claim on a website.

The review takes nine working days rather than the six weeks the CFO feared, because the questions were specific enough that vendors could answer them without escalating. Meridian Pay selects one of the two vendors with a current Type II, sets the acquisition room to view-only with dynamic watermarking on every document, and records the report reference and the bridge letter in its vendor register so the next audit does not repeat the exercise from scratch.

The finding the security lead flags to the board is not about any vendor. It is that two of the six had no attestation and had never been asked for one by a customer, which tells you how often this check is actually run.

7. How SOC 2 sits next to ISO 27001, GDPR, and HIPAA

SOC 2 is one of four frameworks that come up in data room procurement, and buyers routinely treat them as interchangeable. They are not, and knowing which one your counterparty actually needs saves a great deal of time.

ISO 27001 certifies an information security management system against an international standard, issued by an accredited certification body with a three-year cycle and surveillance audits in between. It is more common as a baseline requirement in Europe than SOC 2, which is more common in North America. A vendor may reasonably hold one and not the other.

GDPR is not a certification at all. It is European law, and compliance is a continuing obligation rather than an attestation. What a data room buyer needs from a vendor here is a data processing agreement, a list of sub-processors, a documented transfer mechanism for any data leaving the EU, and, frequently, EU hosting. HIPAA works similarly in the United States for protected health information: what matters is a signed business associate agreement and the safeguards behind it, not a certificate.

FrameworkTypeWho issues itWhat to ask a data room vendor for
SOC 2 Type IIAttestation reportAn independent CPA firmCurrent report under NDA, plus a bridge letter
ISO 27001CertificationAn accredited certification bodyCertificate with scope statement and expiry date
GDPRLawNot issued, it is a legal obligationDPA, sub-processor list, transfer mechanism, hosting region
HIPAALawNot issued, it is a legal obligationSigned business associate agreement

The practical sequence for most deal teams is to require SOC 2 Type II or ISO 27001 as the platform baseline, then layer the legal instruments on top according to what the documents actually contain. A room holding employee records needs the GDPR paperwork whether or not the vendor has a SOC 2.

8. Common mistakes when buying a SOC 2 compliant data room

The first mistake is accepting the word compliant without the noun. SOC 2 compliant is not a defined status. Ask which report, which type, which period, and which criteria, and the answer either arrives immediately or tells you what you needed to know.

The second is filing the report and never revisiting it. A report has an expiry in practical terms, and a vendor register with a three-year-old attestation in it is providing false comfort to whoever reads it next.

The third is assuming the vendor's SOC 2 covers your configuration. It does not. The complementary user entity controls section exists precisely because the auditor knows the customer holds half the responsibility. If your process leaves a bidder's access live for four months after they drop out, no attestation on earth addresses that.

The fourth is over-buying. A SOC 2 compliant data room is a reasonable requirement for any deal involving an enterprise counterparty, a regulated business, or personal data at volume. It is not a reason to move from a €99 monthly plan to a five-figure enterprise contract when the vendor you are already using holds the report. If you are still comparing platforms, our roundup of the best virtual data rooms sets out where each provider's compliance posture sits alongside pricing and bidder management.

Manage due diligence with a virtual data room

No credit card required

Page by page analytics
Unlimited documents & folders
Permission management
Dynamic watermarks
NDA collection
Real-time alerts
Custom branding
Audit trail

9. Data room for your SOC 2 compliance requirements

A data room for SOC 2 compliance has to do two separate jobs, and vendors rarely distinguish between them. The first is being run by an operator that holds the attestation. The second is giving you the controls and the evidence trail to satisfy your own auditors and counterparties about what you did inside it.

Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available). Papermark is SOC 2 Type II compliant, with the audit covering the security, availability, and confidentiality Trust Services Criteria, and privacy addressed through GDPR-aligned controls. It is also GDPR, HIPAA, and CCPA compliant, with AES-256 encryption at rest, TLS in transit, and EU hosting in Frankfurt available. The full posture is on the security page, and the audit scope is detailed in our SOC 2 compliance overview.

Papermark data room interface used for a SOC 2 compliant document review

A SOC 2 compliant data room organised by workstream, with permissions applied per link rather than per user account.

Why you need a data room for SOC 2 compliance

Four reasons a general file-sharing tool fails a security review that a purpose-built room passes.

The attestation has to sit under the product you actually use. A vendor's SOC 2 covers a defined system. When your documents live in a general storage product that was not in the audit scope, the report you filed does not describe the thing holding your data. A data room for SOC 2 compliance is the narrower, auditable surface, which is exactly what makes the scope question answerable.

Auditors ask who saw what, and when. The evidence a SOC 2 auditor or a counterparty's security team wants is an access record: which named viewer opened which document, on what date, from what address, and whether they downloaded it. A shared drive can tell you a link was accessed. A data room produces a per-visitor audit log you can export and attach to the file.

Confidentiality controls have to be demonstrable, not aspirational. Saying that sensitive documents are restricted is a policy. Showing that the security folder was view-only, watermarked, and limited to a four-address allowlist for the duration of the process is evidence. The second one survives a review; the first one does not.

Access has to end when the relationship does. Half of what goes wrong in vendor security reviews is stale access: a bidder who withdrew in March still able to open the room in September. Link-level expiry and instant revocation turn that from a process you have to remember into a setting you configure once.

The rest of this section is the practical build: five steps to a data room for SOC 2 compliance that produces its own evidence.

Step 1: separate the room by sensitivity, not by department

Create folders that map to how restricted the content is rather than to who produced it. In a typical diligence set that means a general folder, a commercial folder, and a restricted folder holding employee records, security documentation, and anything containing personal data. This is the structure that makes the confidentiality criterion answerable later, because you can point to a folder and say who had it.

Automatic file indexing on the Data Rooms Plus plan builds and maintains the index as documents land, which matters because a diligence set arrives in waves rather than complete.

Granular file-level permissions are configured per link rather than per user account, so each counterparty gets a link carrying its own folder scope, email allowlist or domain restriction, and download rule. Nobody has to create an account, which removes the friction that makes busy advisors ignore a room, and the audit record is unaffected.

Granular folder-level permissions applied per counterparty link in a Papermark data room

The restricted folder goes to two named reviewers; everyone else gets the general and commercial folders on the same underlying room.

Step 3: make the restricted material traceable

Set the restricted folder to view-only and switch on dynamic watermarking, which renders the viewer's email, IP address, and timestamp onto every page at the point of display. Add screenshot protection on the documents that would cause the most damage if they circulated.

The honest limit is worth stating in a security review rather than glossed over: a file that has been downloaded cannot be recalled by any platform. That is precisely why download is disabled rather than discouraged on the restricted folder, and why watermarking exists, because it makes a leak traceable to a named viewer instead of merely regrettable.

Dynamic watermark rendering viewer email, IP address, and timestamp on a restricted document

Dynamic watermarking is what turns a confidentiality policy into evidence a reviewer can verify.

Step 4: run questions through Q&A so the record stays intact

Diligence questions arrive continuously and fragment across email threads, which is where disclosure records go to die. The Q&A module attaches each question to the document that prompted it, with permissions controlling which group sees which threads, and the whole log exports for the closing file. When a counterparty later asks what was disclosed and when, the export is the answer.

Step 5: use the audit log as your evidence, then close the room

Page-level analytics and the visitor audit log record every view, download, and NDA acceptance with a timestamp and a named viewer. That is the artefact a security reviewer or an auditor actually wants, and it is also the artefact that lets you spot stale access before someone else does.

Per-visitor analytics showing which reviewer opened which document in a data room

The visitor audit log on Data Rooms Plus is the export that answers who saw what, and when.

When the process ends, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate, so the disclosure record survives the deal team that created it.

Lewis Carhart

Papermark made our fundraising process seamless, providing a clean interface and document analytics we loved.

Lewis Carhart

Founder of CompAI

What it costs

The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data rooms, unlimited documents, a custom domain, dynamic watermarking, NDA agreements, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module with permissions, the visitor audit log, automatic file indexing, a dedicated account manager, and SOC 2 Type II. Data Rooms Premium at €549/month covers 10 team members plus full API access, SSO, whitelabeling, and advanced security controls, and a custom tier adds self-hosted deployment and a bring-your-own AWS bucket.

If your requirement is specifically a SOC 2 compliant data room with an exportable audit log, Data Rooms Plus is the tier that carries both.

FAQ

More useful articles from Papermark

Ready to create your secure data room?