SUSE Corporate SOC2 & SOC3 Compliance Reports
The SOC2 Type 2 and SOC3 are a voluntary compliance programs for service-oriented organizations developed by the American Institute of Certified Public Accountants (AICPA) that outlines how companies are to manage their customer data. The compliance standards are based upon the following Trusted Services Criteria (TSC): 1) Security; 2) Availability; 3) Processing Integrity; 4) Confidentiality; and 5) Privacy.
SOC2 Type 2 and SOC3 reports are tailored to the unique needs of each company and is dependent upon its unique business practices, permitting the company to develop their controls to follow the principles of trust. These are considered internal reports that provide the company, its regulators, partners, and suppliers with important information concerning how the company manages their data.
- SOC2 Type 2 - This report details the operational efficiency of these systems and the auditor's assessment of SUSE's security framework covering managing, processing, and storing customer data according to the five TSC.
- SOC3 - This report reviews SUSE’s internal security controls that are related to the five TSC. The SUSE SOC 3 report provides the same information performed by the auditor during the SOC2 Type 2, but provides a report better suited for customer demands.
SUSE has achieved the following SOC2 Type 2 and SOC3 Compliance Reports:
| Service | Certification | Audit Period |
|---|---|---|
SUSE Corporate |
10/01/2024 - 09/30/2025 |
|
10/01/2024 - 09/30/2025 |
Any questions should be directed to cybersecurity@suse.com.