---
title: "SOC 2 Compliant Data Room 2026: Type I vs II and 9 Vendor Questions"
lang: en
canonical_url: https://www.papermark.com/blog/soc-2-compliant-data-room
last_updated: 2026-08-06
published: 2026-08-06
category: [datarooms]
author: "Marc Seitz"
summary: "What a SOC 2 compliant data room really is in 2026: Type I vs Type II, the 5 Trust Services Criteria, and the 9 questions to ask a VDR vendor before signing."
---

# SOC 2 Compliant Data Room 2026: Type I vs II and 9 Vendor Questions

A SOC 2 compliant data room is a virtual data room whose operator holds a current SOC 2 report from an independent CPA firm, attesting that its controls over customer data meet the AICPA Trust Services Criteria. The report is the evidence. A claim of compliance on a marketing page is not.

## Quick recap

- SOC 2 is an attestation standard from the American Institute of Certified Public Accountants, not a certification body, so no organisation is ever certified in SOC 2 the way it is certified in ISO 27001.
- A SOC 2 Type I report tests whether controls were designed correctly at a single point in time; a Type II report tests whether they operated effectively across a period, usually 6 or 12 months.
- Enterprise procurement asks for Type II. A Type I is normally a staging post while a vendor accumulates the observation window for its first Type II.
- There are five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Only security, the Common Criteria, is mandatory in every SOC 2 audit.
- For a data room, the criteria that matter most are security, confidentiality, and availability. Processing integrity is rarely material because a VDR does not compute anything.
- A SOC 2 report is scoped, so it may cover only part of a vendor's platform. Read the system description before accepting the report.
- Type I typically takes a few weeks to a few months to issue; Type II typically takes 6 to 12 months from kickoff to an issued report.
- Reports carry an audit period with an end date. Anything past that end date needs a bridge letter from the vendor covering the gap.
- Papermark is SOC 2 Type II compliant, with the audit covering the security, availability, and confidentiality criteria; on the data room ladder, SOC 2 Type II sits on the Data Rooms Plus plan at €249/month.

Most buyers of a SOC 2 compliant data room never read the report they asked for. They tick a box in a vendor questionnaire, file the PDF, and move on. That is a shame, because almost everything that matters about a SOC 2 report is in the parts nobody reads: the scope statement, the audit period, the exceptions, and the complementary controls the report assumes you will run yourself.

This guide covers what SOC 2 is, how Type I and Type II differ, which of the five criteria a data room actually needs, what the report does not tell you, and the nine questions to put to a vendor before you sign.

_No credit card required._

## 1. What a SOC 2 compliant data room actually is

SOC 2 stands for System and Organization Controls 2. It is an auditing framework developed by the AICPA for service organisations that hold or process customer data, and it produces a report written by an independent CPA firm rather than a certificate issued by a standards body. That distinction matters more than it sounds: there is no SOC 2 registry to look a vendor up in, so the only way to verify a claim is to read the report.

Applied to a virtual data room, SOC 2 covers the operator, not your deal. The auditor tests how the vendor manages access to its production systems, how it encrypts data, how it onboards and offboards engineers, how it responds to incidents, how it manages changes to the platform, and how it monitors what is happening. A SOC 2 compliant data room therefore tells you something about the company you are trusting with 600 diligence documents, and nothing at all about whether you have configured the permissions on those documents sensibly.

That is the honest framing to carry into a vendor conversation. A SOC 2 report reduces the risk that the platform itself is the weak link. It does not reduce the risk that someone on your side emails a bidder a link with download enabled. Both risks are real, and only one of them is the vendor's job.

The reason the standard has become a purchasing requirement is procurement mechanics rather than security theory. Once a legal team, a bank, or an enterprise customer has a vendor questionnaire, SOC 2 Type II is question one. Vendors that cannot produce the report get filtered before anyone evaluates the product, which is why a SOC 2 compliant data room is now table stakes at the enterprise end of the market rather than a differentiator.

## 2. SOC 2 Type I vs Type II: the distinction procurement cares about

The two report types answer different questions, and confusing them is the most common mistake in vendor review.

A **Type I** report attests to the design of controls at a specific date. The auditor looks at the vendor's control set and forms an opinion on whether, as designed, those controls would meet the relevant criteria. It is a snapshot. It says the vendor has written the right policies and stood up the right systems as of, say, 30 June.

A **Type II** report attests to the operating effectiveness of those same controls across a defined period, typically 6 or 12 months. The auditor samples evidence across the window: access reviews actually performed, tickets actually raised, backups actually tested, offboarding actually completed within the stated window. It is the difference between a vendor saying it revokes engineer access within 24 hours of departure and an auditor confirming that it did so for each of the eleven people who left during the period.

| Dimension | SOC 2 Type I | SOC 2 Type II |
| --- | --- | --- |
| What it tests | Control design at one point in time | Control design plus operating effectiveness over a period |
| Period covered | A single date | Typically 6 or 12 months |
| Typical time to issue | A few weeks to a few months | 6 to 12 months from kickoff |
| Evidence sampled | Policies, configurations, system descriptions | Tickets, logs, access reviews, incident records across the window |
| What procurement accepts | Sometimes, as an interim with a Type II date committed | The standard requirement |
| What it proves about a data room vendor | The controls exist | The controls were followed |

A vendor holding only a Type I is not necessarily a bad choice. Every organisation that has a Type II held a Type I first, because the observation period has to run before it can be audited. What matters is whether the vendor can tell you the date its first Type II period ends and which firm is performing the audit. A vendor that has held a Type I for three years without progressing is a different signal entirely.

## 3. The five Trust Services Criteria and which ones a data room needs

SOC 2 audits are scoped around five Trust Services Criteria. Only one is compulsory; the other four are included at the vendor's election, usually driven by what its customers ask for.

**Security** is the Common Criteria and appears in every SOC 2 audit. It covers logical and physical access controls, encryption, network security, change management, incident response, and monitoring. When someone says a vendor is SOC 2 compliant with no further qualification, this is the part they can be sure was tested.

**Availability** covers whether the system is available for operation as committed: uptime commitments, resilience, capacity planning, backup, and disaster recovery. For a data room this is more material than it first appears. A room that is down during the 48 hours before a bid deadline is a commercial problem, not just an inconvenience.

**Confidentiality** covers information designated as confidential: how it is classified, who can reach it, how long it is retained, and how it is destroyed. For a virtual data room holding an unsigned purchase agreement and a customer contract schedule, this criterion is the one closest to the product's actual purpose.

**Processing integrity** covers whether processing is complete, valid, accurate, timely, and authorised. It matters for systems that calculate things. A data room stores and serves documents rather than computing balances, so this criterion is frequently and legitimately left out of scope.

**Privacy** covers the collection, use, retention, disclosure, and disposal of personal information against the AICPA privacy principles. It overlaps with GDPR without being the same framework, and many vendors address personal data through GDPR-aligned controls and a data processing agreement rather than by adding the privacy criterion to the SOC 2 scope.

| Criterion | In scope by default? | Why it matters for a data room |
| --- | --- | --- |
| Security | Always, it is the Common Criteria | Access control, encryption, and incident response on the platform holding your deal |
| Availability | Elected | Uptime through a bid deadline or a regulator's filing window |
| Confidentiality | Elected | Classification, access, retention, and destruction of deal documents |
| Processing integrity | Elected, rarely relevant | A VDR serves documents rather than computing values |
| Privacy | Elected | Often addressed through GDPR controls and a DPA instead |

The practical test for a buyer is simple. Ask which criteria the report covers, and if the answer is security only, ask why confidentiality was left out of a product whose entire premise is confidentiality.

![Papermark data room security settings showing encryption, access control, and link protection](https://assets.papermark.io/upload/file_8hStraWEA5it3SnUjHpBps-password-protection-cover-papermark-.png)

_Platform controls tested by a SOC 2 audit sit underneath the link-level settings a deal team touches every day._

## 4. What a SOC 2 report does not tell you

A SOC 2 report is a useful document that is routinely over-read. Five things it does not do are worth knowing before you accept one as proof.

**It does not cover everything the vendor sells.** Reports carry a system description defining which services, environments, and locations were in scope. A vendor with a data room, an e-signature product, and an analytics service may have audited one of the three. Read the description, not the cover page.

**It does not run forever.** Every Type II report names an audit period with a start and end date. If today is nine months past that end date, the report tells you about a window that closed nine months ago. The standard remedy is a bridge letter, sometimes called a gap letter, in which the vendor asserts that no material changes occurred between the period end and today. Ask for it.

**It does not mean there were no findings.** Auditors record exceptions where a control did not operate as described, along with management's response. A report with two minor exceptions and a documented remediation is often a better signal than one with none, because it suggests the auditor tested properly. Read the exceptions section.

**It does not do your half of the work.** Most reports list complementary user entity controls, the things the report assumes the customer is doing. For a data room those typically include managing your own user accounts, setting permissions appropriately, and revoking access when a counterparty drops out of a process. If you do not do them, the vendor's SOC 2 does not save you.

**It is not ISO 27001, and it is not GDPR.** SOC 2 is an attestation on controls against AICPA criteria. ISO 27001 certifies an information security management system against an international standard. GDPR is law. A vendor can hold a clean SOC 2 Type II and still be the wrong choice for a deal where personal data leaves the EU. Our [data room compliance guide](/blog/data-room-compliance-guide.md) covers how the frameworks interact.

## 5. The 9 questions to ask a data room vendor about SOC 2

Vendor security questionnaires tend to ask whether a supplier is SOC 2 compliant, accept a yes, and stop. These nine questions take a fifteen-minute call and reliably separate a real attestation from a marketing claim.

| # | Question | What a good answer looks like |
| --- | --- | --- |
| 1 | Is your report Type I or Type II? | Type II, or Type I with a named date for the first Type II period end |
| 2 | What audit period does the current report cover? | A 6 or 12 month window ending within the last 12 months |
| 3 | Which Trust Services Criteria are in scope? | Security plus confidentiality at minimum, availability for most deal workflows |
| 4 | Which of your services are in the system description? | The data room product specifically, named, not the company in general |
| 5 | Which CPA firm performed the audit? | A named firm you can verify, not an unnamed third party |
| 6 | Were there exceptions, and how were they remediated? | A direct answer with dates, rather than a claim of zero findings |
| 7 | Can you provide a bridge letter to today's date? | Yes, issued on request, covering the period since the report end date |
| 8 | What complementary user entity controls do you assume? | A specific list, usually access management and permission configuration |
| 9 | How do I get the report, and under what terms? | Under NDA, within a few working days, without a sales escalation |

Question seven is the one most often skipped and most often revealing. A vendor with a mature compliance function issues bridge letters routinely. A vendor that has never heard the term is telling you something about how many enterprise reviews it has been through.

Question nine is the practical one. A SOC 2 report is a confidential document and no vendor should publish it openly, but the friction involved in obtaining it under NDA is a fair proxy for how the vendor handles security requests generally. Days is normal. Weeks is a warning.

## 6. Worked scenario: a fintech reviews six data room vendors

Meridian Pay is a hypothetical payments company preparing a Series C raise and a simultaneous acquisition of a smaller competitor. Its security team runs vendor reviews for every system that will hold customer or counterparty data, and the data room is the one the CFO wants signed off fastest, because the raise opens in five weeks.

The team shortlists six data room vendors and asks all six the nine questions above. Two return a current SOC 2 Type II report covering security, availability, and confidentiality, with audit periods ending within the previous eight months and bridge letters issued on request. One returns a Type II whose audit period ended nineteen months earlier and cannot produce a bridge letter, which the security lead treats as a fail rather than a delay. One holds a Type I only, with a stated Type II period ending in four months, which is a plausible answer from a growing vendor but does not clear procurement for a system holding acquisition documents. Two produce no attestation at all and offer a security whitepaper instead.

The review takes nine working days rather than the six weeks the CFO feared, because the questions were specific enough that vendors could answer them without escalating. Meridian Pay selects one of the two vendors with a current Type II, sets the acquisition room to view-only with dynamic watermarking on every document, and records the report reference and the bridge letter in its vendor register so the next audit does not repeat the exercise from scratch.

The finding the security lead flags to the board is not about any vendor. It is that two of the six had no attestation and had never been asked for one by a customer, which tells you how often this check is actually run.

## 7. How SOC 2 sits next to ISO 27001, GDPR, and HIPAA

SOC 2 is one of four frameworks that come up in data room procurement, and buyers routinely treat them as interchangeable. They are not, and knowing which one your counterparty actually needs saves a great deal of time.

ISO 27001 certifies an information security management system against an international standard, issued by an accredited certification body with a three-year cycle and surveillance audits in between. It is more common as a baseline requirement in Europe than SOC 2, which is more common in North America. A vendor may reasonably hold one and not the other.

GDPR is not a certification at all. It is European law, and compliance is a continuing obligation rather than an attestation. What a data room buyer needs from a vendor here is a data processing agreement, a list of sub-processors, a documented transfer mechanism for any data leaving the EU, and, frequently, EU hosting. HIPAA works similarly in the United States for protected health information: what matters is a signed business associate agreement and the safeguards behind it, not a certificate.

| Framework | Type | Who issues it | What to ask a data room vendor for |
| --- | --- | --- | --- |
| SOC 2 Type II | Attestation report | An independent CPA firm | Current report under NDA, plus a bridge letter |
| ISO 27001 | Certification | An accredited certification body | Certificate with scope statement and expiry date |
| GDPR | Law | Not issued, it is a legal obligation | DPA, sub-processor list, transfer mechanism, hosting region |
| HIPAA | Law | Not issued, it is a legal obligation | Signed business associate agreement |

The practical sequence for most deal teams is to require SOC 2 Type II or ISO 27001 as the platform baseline, then layer the legal instruments on top according to what the documents actually contain. A room holding employee records needs the GDPR paperwork whether or not the vendor has a SOC 2.

## 8. Common mistakes when buying a SOC 2 compliant data room

The first mistake is accepting the word compliant without the noun. SOC 2 compliant is not a defined status. Ask which report, which type, which period, and which criteria, and the answer either arrives immediately or tells you what you needed to know.

The second is filing the report and never revisiting it. A report has an expiry in practical terms, and a vendor register with a three-year-old attestation in it is providing false comfort to whoever reads it next.

The third is assuming the vendor's SOC 2 covers your configuration. It does not. The complementary user entity controls section exists precisely because the auditor knows the customer holds half the responsibility. If your process leaves a bidder's access live for four months after they drop out, no attestation on earth addresses that.

The fourth is over-buying. A SOC 2 compliant data room is a reasonable requirement for any deal involving an enterprise counterparty, a regulated business, or personal data at volume. It is not a reason to move from a €99 monthly plan to a five-figure enterprise contract when the vendor you are already using holds the report. If you are still comparing platforms, our roundup of the [best virtual data rooms](/blog/best-virtual-data-rooms.md) sets out where each provider's compliance posture sits alongside pricing and bidder management.

## 9. Data room for your SOC 2 compliance requirements

A **data room for SOC 2 compliance** has to do two separate jobs, and vendors rarely distinguish between them. The first is being run by an operator that holds the attestation. The second is giving you the controls and the evidence trail to satisfy your own auditors and counterparties about what you did inside it.

[Papermark](/data-room.md) is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available). Papermark is **SOC 2 Type II compliant**, with the audit covering the security, availability, and confidentiality Trust Services Criteria, and privacy addressed through GDPR-aligned controls. It is also GDPR, HIPAA, and CCPA compliant, with AES-256 encryption at rest, TLS in transit, and EU hosting in Frankfurt available. The full posture is on the [security page](https://www.papermark.com/security.md), and the audit scope is detailed in our [SOC 2 compliance overview](/blog/papermark-soc2-compliance.md).

![Papermark data room interface used for a SOC 2 compliant document review](https://img.papermarkassets.com/upload/file_35DtVER7SdS1G6unRE8unv-papermark-data-room.png)

_A SOC 2 compliant data room organised by workstream, with permissions applied per link rather than per user account._

### Why you need a data room for SOC 2 compliance

Four reasons a general file-sharing tool fails a security review that a purpose-built room passes.

**The attestation has to sit under the product you actually use.** A vendor's SOC 2 covers a defined system. When your documents live in a general storage product that was not in the audit scope, the report you filed does not describe the thing holding your data. A data room for SOC 2 compliance is the narrower, auditable surface, which is exactly what makes the scope question answerable.

**Auditors ask who saw what, and when.** The evidence a SOC 2 auditor or a counterparty's security team wants is an access record: which named viewer opened which document, on what date, from what address, and whether they downloaded it. A shared drive can tell you a link was accessed. A data room produces a per-visitor audit log you can export and attach to the file.

**Confidentiality controls have to be demonstrable, not aspirational.** Saying that sensitive documents are restricted is a policy. Showing that the security folder was view-only, watermarked, and limited to a four-address allowlist for the duration of the process is evidence. The second one survives a review; the first one does not.

**Access has to end when the relationship does.** Half of what goes wrong in vendor security reviews is stale access: a bidder who withdrew in March still able to open the room in September. Link-level expiry and instant revocation turn that from a process you have to remember into a setting you configure once.

The rest of this section is the practical build: five steps to a data room for SOC 2 compliance that produces its own evidence.

### Step 1: separate the room by sensitivity, not by department

Create folders that map to how restricted the content is rather than to who produced it. In a typical diligence set that means a general folder, a commercial folder, and a restricted folder holding employee records, security documentation, and anything containing personal data. This is the structure that makes the confidentiality criterion answerable later, because you can point to a folder and say who had it.

**Automatic file indexing** on the Data Rooms Plus plan builds and maintains the index as documents land, which matters because a diligence set arrives in waves rather than complete.

### Step 2: set permissions per link and keep the restricted folder narrow

**Granular file-level permissions** are configured per link rather than per user account, so each counterparty gets a link carrying its own folder scope, email allowlist or domain restriction, and download rule. Nobody has to create an account, which removes the friction that makes busy advisors ignore a room, and the audit record is unaffected.

![Granular folder-level permissions applied per counterparty link in a Papermark data room](https://assets.papermark.io/upload/file_LkU4BNY6MKUKMgDucSzzFg-papermark-granular-permissions.png)

_The restricted folder goes to two named reviewers; everyone else gets the general and commercial folders on the same underlying room._

### Step 3: make the restricted material traceable

Set the restricted folder to view-only and switch on **dynamic watermarking**, which renders the viewer's email, IP address, and timestamp onto every page at the point of display. Add **screenshot protection** on the documents that would cause the most damage if they circulated.

The honest limit is worth stating in a security review rather than glossed over: a file that has been downloaded cannot be recalled by any platform. That is precisely why download is disabled rather than discouraged on the restricted folder, and why watermarking exists, because it makes a leak traceable to a named viewer instead of merely regrettable.

![Dynamic watermark rendering viewer email, IP address, and timestamp on a restricted document](https://assets.papermark.io/upload/file_Ks2dtpU7UXaoreiAAtXr54-watermarked-document.png)

_Dynamic watermarking is what turns a confidentiality policy into evidence a reviewer can verify._

### Step 4: run questions through Q&A so the record stays intact

Diligence questions arrive continuously and fragment across email threads, which is where disclosure records go to die. The **Q&A module** attaches each question to the document that prompted it, with permissions controlling which group sees which threads, and the whole log exports for the closing file. When a counterparty later asks what was disclosed and when, the export is the answer.

### Step 5: use the audit log as your evidence, then close the room

**Page-level analytics** and the **visitor audit log** record every view, download, and NDA acceptance with a timestamp and a named viewer. That is the artefact a security reviewer or an auditor actually wants, and it is also the artefact that lets you spot stale access before someone else does.

![Per-visitor analytics showing which reviewer opened which document in a data room](https://assets.papermark.io/upload/file_YVZLbYwELYa8SxfjBg3mGe-virtual-data-room-analytics-.png)

_The visitor audit log on Data Rooms Plus is the export that answers who saw what, and when._

When the process ends, **data room freeze** makes the room immutable and exports it as an archived ZIP with a certificate, so the disclosure record survives the deal team that created it.

### What it costs

The [Data Rooms plan](https://www.papermark.com/pricing.md?view=datarooms) is **€99/month** with a 7-day free trial and includes **3 team members**, unlimited data rooms, unlimited documents, a custom domain, dynamic watermarking, NDA agreements, and granular file-level permissions. **Data Rooms Plus at €249/month** adds **5 team members**, the Q&A module with permissions, the visitor audit log, automatic file indexing, a dedicated account manager, and **SOC 2 Type II**. **Data Rooms Premium at €549/month** covers **10 team members** plus full API access, SSO, whitelabeling, and advanced security controls, and a custom tier adds self-hosted deployment and a bring-your-own AWS bucket.

If your requirement is specifically a SOC 2 compliant data room with an exportable audit log, Data Rooms Plus is the tier that carries both.

## FAQ

### What is a SOC 2 compliant data room?

It is a virtual data room whose operator holds a current SOC 2 report from an independent CPA firm covering the AICPA Trust Services Criteria. The report attests to the vendor's controls over customer data across an audit period, typically 6 or 12 months for a Type II. It says nothing about how you configure permissions inside the room, which is the customer's half of the responsibility.

### What is the difference between SOC 2 Type 1 and Type 2?

Type I tests whether controls were designed correctly at a single point in time and typically takes a few weeks to a few months to issue. Type II tests whether those controls actually operated across a period of 6 or 12 months and typically takes 6 to 12 months from kickoff. Enterprise procurement asks for Type II; a Type I is normally an interim while the observation window runs.

### Is SOC 2 a certification?

No. SOC 2 is an attestation standard from the AICPA, so a CPA firm issues a report rather than a certification body issuing a certificate. That is why the correct phrasing is SOC 2 compliant or SOC 2 attested rather than SOC 2 certified, and why the only way to verify a claim is to read the report. ISO 27001, by contrast, is a genuine certification with a three-year cycle.

### What are the 5 Trust Services Criteria?

Security, availability, processing integrity, confidentiality, and privacy. Only security, known as the Common Criteria, is mandatory in every SOC 2 audit; the other four are elected by the vendor. For a data room the important ones are security, confidentiality, and availability, and processing integrity is usually left out because a VDR serves documents rather than computing values.

### Does a data room need to be SOC 2 compliant?

It depends on the counterparty. Any process involving an enterprise buyer, a regulated business, a bank, or personal data at volume will almost always meet a vendor questionnaire that asks for SOC 2 Type II as question one. A friends-and-family seed round will not. Where it is required, it is a filter applied before the product is evaluated, so a vendor without the report never reaches the shortlist.

### How do I ask a vendor for their SOC 2 report?

Request it under NDA and expect it within a few working days. Ask 4 things alongside it: the report type, the audit period start and end dates, which Trust Services Criteria are in scope, and which services appear in the system description. If the report period ended more than a few months ago, also ask for a bridge letter covering the gap to today.

### What is a SOC 2 bridge letter?

A bridge letter, sometimes called a gap letter, is a statement from the vendor asserting that no material changes to its control environment occurred between the end of the audit period and the current date. It exists because a Type II report covers a closed window of 6 or 12 months, and buyers usually receive it several months after that window ended. Any vendor with a mature compliance function issues them on request.

### How long does SOC 2 Type II take to get?

Typically 6 to 12 months from kickoff to an issued report, because the audit period itself has to run before the auditor can sample evidence from it. A Type I can be issued in a few weeks to a few months, which is why growing vendors publish a Type I first and commit to a Type II period end date. Ask for that date rather than accepting a general commitment.

### Is Papermark SOC 2 compliant?

Yes. Papermark is SOC 2 Type II compliant, with the audit covering the security, availability, and confidentiality Trust Services Criteria and privacy addressed through GDPR-aligned controls. On the data room plan ladder, SOC 2 Type II sits on Data Rooms Plus at €249/month alongside the visitor audit log and the Q&A module. Papermark is also GDPR, HIPAA, and CCPA compliant, and the report is available to enterprise customers under NDA.

### Does SOC 2 cover GDPR?

No. SOC 2 is an attestation on controls against AICPA criteria, while GDPR is European law and a continuing obligation. A vendor can hold a clean SOC 2 Type II and still lack the paperwork a GDPR review needs, which is a data processing agreement, a sub-processor list, a documented transfer mechanism for data leaving the EU, and a hosting region you can name. Ask for both separately.

### What are complementary user entity controls?

They are the controls a SOC 2 report assumes the customer operates rather than the vendor. For a data room that usually means managing your own users, configuring permissions appropriately, and revoking counterparty access when someone leaves a process. They are listed in the report and are the single most skipped section, which is why stale bidder access is the most common finding in a deal-side security review.

### Can I get a SOC 2 compliant data room for under €300 a month?

Yes. Papermark's Data Rooms Plus plan is €249/month for 5 team members and includes SOC 2 Type II, the visitor audit log, the Q&A module, and automatic file indexing, with unlimited data rooms and unlimited documents. The €99/month Data Rooms plan covers 3 team members with watermarking and granular permissions but does not carry the SOC 2 Type II line, so Plus is the tier to pick when the attestation is the requirement.

## Related resources

- [Best virtual data rooms in 2026](/blog/best-virtual-data-rooms.md)
- [Papermark data room](/data-room.md)
- [Data room compliance guide](/blog/data-room-compliance-guide.md)
- [Papermark SOC 2 Type II compliance](/blog/papermark-soc2-compliance.md)
- [Papermark GDPR compliance](/blog/papermark-gdpr-compliance.md)
- [Data room checklist for 2026](/blog/data-room-checklist-2026.md)
- [Cybersecurity due diligence](/blog/cybersecurity-due-diligence.md)

---

_Markdown version of [this article](https://www.papermark.com/blog/soc-2-compliant-data-room) for AI agents and LLMs._
_More Papermark content: [llms.txt](https://www.papermark.com/llms.txt) · [full index](https://www.papermark.com/llms-full.txt)._
