GetSOC2

The Compliance Brief for SOC 2 buyers

Every Tuesday, the stories from the past week that change something for a company buying or holding a SOC 2 report, with a plain take on each.

Last reviewed 2026-09-29Written by Jacob Masse, TrazTech Inc.

Most of what reaches a SOC 2 buyer's inbox is vendor marketing. The Compliance Brief is the other thing: what happened that week to companies like yours and to the vendors in your own report, and what a customer's security reviewer is going to ask about it next.

Below are the stories from recent issues that bear on SOC 2: vendor and subprocessor breaches, what auditors are looking at, and the contract terms customers are starting to write. Each one links to the full take.

Latest on SOC 2 audits, auditors and vendor reviews

Every issue on GetSOC2

Every issue in full, including the stories outside SOC 2 audits, auditors and vendor reviews, is in the archive on traztech.ca. Issues with nothing on SOC 2 audits, auditors and vendor reviews are listed there and not here.

Questions

How often does The Compliance Brief arrive?

Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for companies buying a SOC 2 audit.

What does it cost?

Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates GetSOC2. There is no paid tier.

Will signing up here send me anything else?

No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.

How do I stop it?

Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.