SUSE Industrial Edge - SOC2 Compliance Reports
SOC 2 Type 2 and SOC 3 are voluntary compliance programs for service-oriented organizations, developed by the American Institute of Certified Public Accountants (AICPA), that outline how companies manage and protect customer data. The overall AICPA framework defines five Trust Services Criteria (TSC): 1) Security; 2) Availability; 3) Processing Integrity; 4) Confidentiality; and 5) Privacy. Each organization selects the criteria relevant to its own systems and services. SUSE's SOC 2 Type 2 and SOC 3 examinations cover the Security and Confidentiality Trust Services Categories, applied to SUSE's Corporate, StackState, and Hosted Rancher systems.
SOC 2 Type 2 – This report details the suitability of the design and the operating effectiveness of SUSE's internal controls over the examination period, covering how SUSE manages, processes, and stores customer data in alignment with the Security and Confidentiality criteria. Because it contains sensitive operational detail, this report is shared with customers and partners under a Non-Disclosure Agreement (NDA).
SOC 3 – This is the public-facing counterpart to the SOC 2 Type 2 report, covering the same Security and Confidentiality criteria in a summarized, general-use format that can be shared without an NDA.
| Service | Certification | Audit Period |
|---|---|---|
SUSE Industrial Edge |
10/01/2024 - 09/30/2025 |
Any questions should be directed to cybersecurity@suse.com.