HomeStandards › SOC 2

Framework

SOC 2 and mobile apps

How does SOC 2 relate to mobile apps?

SOC 2 is a way for a service organisation to show it handles customer data securely, judged against a set of trust-services criteria. It is not mobile-specific, but criteria around security, change management and managing vulnerabilities apply to how you build and test software.

If your product includes a mobile app, testing it and tracking the findings is part of demonstrating those controls operate.

How Mobexa helps

Mobexa provides repeatable mobile testing and signed, exportable evidence of findings and their resolution. That evidence supports the security and vulnerability-management controls a SOC 2 examination looks at for the software you ship.

Common questions

Is SOC 2 specific to mobile apps?
No. SOC 2 covers how a service organisation protects customer data overall. Mobile app testing supports specific controls within it, such as secure development and vulnerability management.

Mobexa maps every finding on your Android and iOS builds to SOC 2 and the other standards an auditor recognises.

Start Free Trial