Anyone have experience with needing SOC 2 compliance to consult with agencies? I've heard instances where people think it's not necessary (as consultants, we're using Salesforce so the audit would be on Salesforce not on us) and instances where people think it is (if we're accessing privileged information audits apply) Note:I only learned the phrase SOC 2 in the last week so very junior to this convo but interested to hear what others' experience has been. Thoughts?? #Salesforce Developer
Hi Cecilia,
It generally depends on the scope of the consulting engagement and what access the consultant has to the client's systems and data.
Using Salesforce does not automatically mean that the consultant's organization is covered by Salesforce's SOC 2 report. Salesforce's compliance applies to Salesforce's services, while a consultant may have separate security and compliance responsibilities based on the services they provide, how they access client systems, and the client's contractual requirements.
If the client requires SOC 2 compliance as part of the engagement, they may ask the consulting company to provide its own SOC 2 report or other security documentation, even if Salesforce is the underlying platform.
I would recommend checking the specific contract/security requirements with the client and, if necessary, confirming the requirements with a security or compliance professional.