SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA (American Institute of Certified Public Accountants). It is not government legislation or a certification scheme but a voluntary attestation standard — however, it has become a de facto market requirement for any technology company, cloud service provider, or SaaS vendor serving enterprise customers, particularly in the US. A SOC 2 report is produced by an independent CPA firm that evaluates an organization’s controls against the AICPA’s Trust Services Criteria (TSC), organized in five categories: Security (mandatory for all SOC 2 reports, covering Common Criteria CC1–CC9), Availability, Processing Integrity, Confidentiality, and Privacy (each optional depending on the organization’s services and customer commitments). The Common Criteria (CC1–CC9) are derived from the COSO Internal Control Framework and cover control environment, risk assessment, monitoring, logical/physical access, system operations, change management, and risk mitigation. There are two report types: Type I (evaluates control design at a point in time) and Type II (evaluates both design and operating effectiveness over 6–12 months — the standard enterprise customers demand). SOC 2 reports are restricted-use documents shared with customers under NDA. While not legally mandatory, major enterprises, financial institutions, and regulated industries routinely require SOC 2 Type II reports from their vendors before signing contracts, making it an essential market-access requirement for technology service providers.
Red Hat holds SOC 2 Type II attestation for its cloud-hosted services, demonstrating that the controls governing Red Hat’s managed offerings (including Red Hat OpenShift Dedicated, ROSA, and Red Hat Insights) operate effectively over sustained periods. For Red Hat’s customers who must produce their own SOC 2 reports, the Red Hat platform provides the technical controls that map to Trust Services Criteria across all nine Common Criteria series. For CC6 (Logical and Physical Access): OpenShift RBAC, namespace isolation, network policies, and integration with enterprise identity providers enforce least-privilege access; RHEL’s PAM, SELinux, and audit subsystems provide OS-level access control evidence. For CC7 (System Operations): Red Hat Advanced Cluster Security delivers continuous monitoring, vulnerability detection, and runtime anomaly alerting; Red Hat Insights provides predictive analytics and drift detection. For CC8 (Change Management): OpenShift’s GitOps-based deployment model, Ansible’s idempotent playbooks, and the Operator lifecycle provide the auditable, version-controlled change management SOC 2 auditors verify. For Availability criteria: OpenShift’s self-healing operators, multi-cluster management, and Ansible-driven DR orchestration demonstrate the resilience controls auditors test. Red Hat’s shared responsibility documentation clearly delineates which SOC 2 controls are inherited from Red Hat’s managed services versus those customers must implement themselves — critical for scoping a customer’s own SOC 2 audit boundary.
