Info: Does Venafi support SOC 2 and/or SSAE 16?


Applies To:

  • Venafi as a Service (VaaS aka Venafi Cloud)

Note: Trust Protection Platform (TPP) is an on-premise solution and an SSAE 16 isn’t applicable.


SOC 2 is the internet standard Service Organization Control 2 for reporting regarding outsourced  tasks and functions. SSAE 16 is the older standard Statement on Standards for Attestation Engagements 16.  

More Info:

Official Statement

The intent of an SSAE 16 is to address multiple controls for services organizations that hold customer data. One example would be a business offering Software as a Service, or, SaaS.

With our focus on security, availability, processing integrity, and confidentiality we have completed our assessment and expect to receive our SOC2 Type 1 in early 2022 and will update this article as it completes.

Was this article helpful?
0 out of 0 found this helpful