The Compliance Brief for SOC 2 buyers
Every Tuesday, the stories from the past week that change something for a company buying or holding a SOC 2 report, with a plain take on each.
Most of what reaches a SOC 2 buyer's inbox is vendor marketing. The Compliance Brief is the other thing: what happened that week to companies like yours and to the vendors in your own report, and what a customer's security reviewer is going to ask about it next.
Below are the stories from recent issues that bear on SOC 2: vendor and subprocessor breaches, what auditors are looking at, and the contract terms customers are starting to write. Each one links to the full take.
Free weekly email
Get the next issue on Tuesday
Join the list and the next issue arrives Tuesday morning. Or read a few below first.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Latest on SOC 2 audits, auditors and vendor reviews
- Your AI agents are logging in as humans and SOC 2 cannot tell
A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed. - Revolut handed over customer data to someone pretending to be a government
Revolut confirmed that an unauthorized party obtained customer information by submitting a fraudulent data request from a legitimate government email domain. - Trezor's supplier breach keeps growing, and it was never Trezor's system
Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. - Revolut gave customer data to someone posing as a government agency
Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. - McKesson tells the SEC it was hit through third-party applications
McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. - An ID verification vendor appears to be the source of 153 million licence scans
A new dark web identity theft service is selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada. - McKesson breach came through third-party applications
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. - JFrog Artifactory flaw lands in the KEV catalogue
CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory.
Every issue on GetSOC2
- Issue 8: Your AI agents are logging in as humans and SOC 2 cannot tell
- Issue 7: Revolut handed over customer data to someone pretending to be a government
- Issue 6: Trezor's supplier breach keeps growing, and it was never Trezor's system
- Issue 5: McKesson tells the SEC it was hit through third-party applications
- Issue 4: McKesson breach came through third-party applications
- Issue 3: Defence contractors do not believe their own CMMC scores
- Issue 2: A year-long campaign is quietly draining Salesforce and ServiceNow tenants
- Issue 1: LexisNexis pulled products offline over a third-party vendor incident
Every issue in full, including the stories outside SOC 2 audits, auditors and vendor reviews, is in the archive on traztech.ca. Issues with nothing on SOC 2 audits, auditors and vendor reviews are listed there and not here.
Questions
How often does The Compliance Brief arrive?
Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for companies buying a SOC 2 audit.
What does it cost?
Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates GetSOC2. There is no paid tier.
Will signing up here send me anything else?
No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.
How do I stop it?
Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.
Free weekly email
Get it every Tuesday
One email a week on SOC 2 audits, auditors and vendor reviews. Free, and one click to leave.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.