SOC 2 compliance statistics
How many companies are SOC 2 compliant, the most common frameworks, the top auditors, and how verification breaks down. Drawn from public trust centers and reviewed reports, never self-attested.
SOC2C is an independent directory, not an official SOC 2 registry. SOC 2 is a private attestation report issued by a licensed CPA firm under AICPA standards. The AICPA does not operate a public registry of SOC 2-compliant companies, no body certifies SOC 2 status, and SOC2C is not affiliated with the AICPA, any audit firm, or any trust center platform. The figures below describe what companies publish on their own trust centers as recorded here — they are neither an authoritative nor a complete picture of the market. How listings work
Most common frameworks
- SOC 2 Type II4,675 companies · 65%
- GDPR1,709 companies · 24%
- ISO 270011,260 companies · 17%
- HIPAA1,160 companies · 16%
- CCPA649 companies · 9%
- PCI DSS607 companies · 8%
- SOC 2 Type I267 companies · 4%
- NIST CSF142 companies · 2%
Verification levels
- Listed7,241 · 100%
- Domain Verified2 · 0%
- Report Verified2 · 0%
- Live Verified0 · 0%
Top auditors
By region
- United States2,566
- European Union340
- United Kingdom213
- Canada176
- Australia155
By category
Methodology
Figures are computed live from the SOC2C registry. Compliance signals are sourced from companies' public trust centers and security pages; each listing carries a graded verification level — from Listed (public information) to Report Verified (the SOC2C team reviewed the report and cross-referenced the auditor). Nothing here is self-attested.
Listings compiled from public sources record document titles only — SOC2C does not scrape or host those files. A company that claims its profile may upload documents to SOC2C; those are reviewed by our team and released under the company's own control. SOC2C makes no certification of its own, and a listing is not a substitute for reading a company's SOC 2 report.