
Field Effect
Trust level
Report Verified
Independently verified
Listed
Domain
Report
Live
The SOC2C verification team reviewed the company's uploaded SOC 2 report and cross-referenced the auditor against AICPA-registered CPA firms.
SOC 2 report confirmed; auditor MHM cross-referenced● Verified Jan 2026
Field Effect is SOC 2 Type II compliant, audited by MHM, with its most recent report dated Jan 2026. Field Effect also holds ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, and NIST CSF.
About
Managed detection and response (MDR) and cybersecurity for SMBs.
Compliance & infrastructure
Key controls
- ✓Encryption at rest
- ✓Encryption in transit
- ✓MFA / SSO enforced
- ✓Annual pen test
- ✓BCP / DR
Hosting
AWS
Penetration test
Unknown. Field Effect's penetration test vendor isn't listed yet.
Complete this profile
9/11 details · 82%SOC2C shows the verified essentials. 2 details are not yet provided. Trust centers list more, so we invite the owner to fill the gaps here.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- SubprocessorsList your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Frequently asked
Is Field Effect SOC 2 compliant?
Field Effect is SOC 2 Type II compliant, audited by MHM, with its most recent report dated Jan 2026. On SOC2C this listing is Report Verified.
Who audited Field Effect?
MHM.
When does Field Effect's SOC 2 renew?
Field Effect's SOC 2 is due to renew in Jan 2027.
Is Field Effect ISO 27001 certified?
According to Field Effect's public trust center, Field Effect is ISO 27001 certified. On SOC2C this listing is Report Verified.
Is Field Effect HIPAA compliant?
According to Field Effect's public trust center, Field Effect is HIPAA compliant. On SOC2C this listing is Report Verified.
Is Field Effect PCI DSS compliant?
According to Field Effect's public trust center, Field Effect is PCI DSS compliant. On SOC2C this listing is Report Verified.
Is Field Effect GDPR compliant?
According to Field Effect's public trust center, Field Effect is GDPR compliant. On SOC2C this listing is Report Verified.
Is Field Effect CMMC compliant?
According to Field Effect's public trust center, Field Effect is CMMC compliant. On SOC2C this listing is Report Verified.
Is Field Effect NIST CSF compliant?
According to Field Effect's public trust center, Field Effect is NIST CSF compliant. On SOC2C this listing is Report Verified.
Is Field Effect SOC 2 Type I or Type II?
Field Effect is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Who audited Field Effect's SOC 2?
Field Effect's SOC 2 was audited by MHM. SOC2C cross-references the auditor before a listing earns the Report Verified badge.
Can I use Field Effect's SOC 2 for a vendor risk assessment?
Yes. Field Effect's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Field Effect penetration tested?
Yes — Field Effect undergoes third-party penetration testing as part of its security program. The pentest vendor is listed on its SOC2C profile.
Is Field Effect secure?
Security isn't a single yes/no, but Field Effect is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, NIST CSF, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Field Effect have a bug bounty or vulnerability disclosure program?
Field Effect hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@fieldeffect.com or via a /security page.
Who are Field Effect's subprocessors?
Field Effect's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Field Effect host or store data?
Field Effect hosts on AWS. Data residency details are on its trust center.
Does Field Effect encrypt data?
Yes — Field Effect encrypts data at rest and in transit, per its trust center.
Does Field Effect enforce MFA or SSO?
Yes — Field Effect enforces multi-factor authentication / single sign-on, per its security controls.
Where is Field Effect's trust center or security page?
Field Effect's trust center is at https://trust.fieldeffect.com/. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
