What is a SOC 2 report and does a dealership software vendor need one?
A SOC 2 is an independent auditor's report on how a service organisation controls security and related criteria. No rule requires a dealership vendor to hold one, but for any vendor touching customer or financial data it is the most common way to evidence controls without running your own audit. A Type II report, which covers a period of operation rather than a point in time, is the one worth asking for.
Type I and Type II are not interchangeable
Type I says controls were designed appropriately on a date. Type II says they operated effectively across a period, usually six to twelve months. Ask which one you are being shown and what period it covers.
Read the exceptions and the scope
The value is in the detail, not the logo. Check which systems are in scope, which trust criteria are included, and what exceptions the auditor recorded. A report scoped to a product you are not buying tells you nothing.
Absence is not disqualifying
Smaller and newer providers often have real controls and no report, because an audit is expensive. Where there is no SOC 2, ask for a completed security questionnaire, penetration-test summary, subprocessor list and incident-response commitment, and put the answers in the contract.
Re-check it
A report expires. Make annual re-provision a contractual obligation rather than something you have to chase.
What to verify
Ask whether the report is Type I or Type II and what period it covers
Read the scope and the auditor's exceptions, not the logo
Where there is no report, require a completed security questionnaire
Make annual re-provision a contractual obligation
Continue the research
Related dealership technology questions
What should a dealer ask before signing a software contract?
Confirm the exact products, implementation, service levels, data rights, security obligations, fees, renewal mechanics, price changes, termination, transition support and order-of-precedence across every incorporated document. Obtain qualified legal review for the dealer’s situation.
Vendor security reviewWhat security questions should dealerships ask software vendors?
Ask about governance, independent assessments, access control, encryption, logging, vulnerability management, incident response, resilience, data retention, subprocessors and contract obligations. Scope the review to the actual service and data involved.
Vendor acquisition diligenceWhat should dealers do when a software vendor is acquired or rebranded?
Confirm the legal contracting entity, product roadmap, support organization, data practices, integrations, pricing, renewal terms, account ownership and any required consent. A rebrand may be cosmetic; an acquisition may change dependencies or commercial terms, but neither should be assumed.
Safeguards RuleWhat is the FTC Safeguards Rule for dealerships?
Because dealerships arrange financing and leasing, they are treated as financial institutions under the Gramm-Leach-Bliley Act and fall under the FTC's Safeguards Rule. The Rule requires a written information security program with named elements — including a designated qualified individual, a written risk assessment, encryption, multi-factor authentication and vendor oversight. The amended requirements became mandatory on June 9, 2023. This is issue-spotting information, not legal advice.