Trust is the bedrock of the financial services industry.
In communities across the country, account holders trust their institution to safeguard both their funds and their data. And once that trust is established, it has to be maintained throughout the relationship â both by the institution and its chosen tech partners.
So, how can financial institutions establish that a vendor is trustworthy when spam, scams, and data breaches abound? When choosing a digital banking provider, payments processor, or marketing platform, independent verification is paramount.
Thatâs where SOC 2 Type II compliance comes in.
Key Takeaways
What is SOC 2 Compliance?
SOC (System and Organization Controls) 2 compliance is a way for tech providers to demonstrate that they have controls in place for protecting systems and information entrusted to them.
The framework comes from the American Institute of Certified Public Accountants (AICPA) and is built around established standards known as the Trust Services Criteria. These criteria address:
Importantly, SOC 2 involves more than a companyâs claims that its systems are secure. An independent CPA examines the organizationâs controls against criteria included in the scope and issues a SOC 2 report based on the findings.
Why Does SOC 2 Type II Compliance Matter?
For financial institutions, trusting a technology provider means trusting how they handle important systems and data.
Rather than relying solely on a vendorâs own security claims, institutions can look to an examination conducted by an independent CPA. That assurance is especially relevant to financial services cybersecurity, where third-party technology can extend an institutionâs risk beyond its own walls.
SOC 2 Type II doesnât guarantee that a security incident will never occur, nor does it replace an institutionâs own vendor due diligence. Instead, it provides evidence that specified controls have been independently examined.
For banks and credit unions, that provides another valuable piece of information when deciding which technology partners to trust with their data.
How Does a SOC 2 Type II Examination Work?
A SOC 2 Type II examination requires an organization to demonstrate that its controls donât just exist on paper â they work in practice. While CPAs lead these examinations, they may work alongside professionals with expertise in information technology and cybersecurity.
Although every examination is different, the process generally involves:

The process requires extensive documentation and testing. Type II observation periods commonly span several months, with additional auditor testing and reporting before the final report is issued.
What are the SOC 2 Trust Services Criteria?
The Trust Services Criteria define the areas of a system that SOC 2 controls may address. Security is foundational to every SOC 2 examination, while availability, processing integrity, confidentiality, and privacy may be included depending on the organization, its services, and the scope of the examination.
Security
Security focuses on protecting systems and information against unauthorized access, disclosure, or damage. SOC 2 security controls can include measures related to user access, authentication, system monitoring, and other safeguards designed to protect information and the systems that store or process it.
Availability
Availability addresses whether systems and information are accessible for operation and use as committed or agreed. Relevant controls may address system performance, monitoring, recovery, and other measures intended to keep services available when disruptions occur.
Processing Integrity
Processing integrity focuses on whether a system performs its intended functions completely, accurately, and on time. It also considers whether processing is valid and authorized â establishing that a system handles information the way it is supposed to.
Confidentiality
Confidentiality addresses how information designated as confidential is protected. That can include safeguards governing how sensitive information is accessed, stored, transmitted, and disposed of so that it remains protected throughout its lifecycle.
Privacy
Privacy focuses on how an organization collects and uses personal information. It considers whether that information is handled for appropriate purposes and in accordance with the organizationâs privacy commitments, including practices around consent, use, disclosure, and retention.
Do I Need to Choose a SOC 2 Type II Compliant Technology Provider?
Not necessarily. Financial regulators generally do not require banks and credit unions to work exclusively with SOC 2 Type II compliant vendors. Instead, they place responsibility for evaluating third-party risk on the financial institution itself.

For banks, guidance from the Federal Reserve, FDIC, and OCC calls for risk-based due diligence when selecting third parties, along with appropriate oversight throughout the relationship. The NCUA similarly emphasizes a credit unionâs responsibility to evaluate and monitor its third-party relationships.
In other words, SOC 2 Type II may not be a universal requirement for your technology partners â but evaluating the risks associated with those partners is your institutionâs responsibility.
Trust Should Be More Than a Promise
Financial institutions have always been built on trust. The technology providers they choose should be prepared to earn it, too.
SOC 2 Type II compliance provides something more substantial than assurances about financial data protection. Through independent examination and evidence of how specified controls operate over time, it gives financial institutions another meaningful way to evaluate their technology partners.
Connect by Main Streetâĸ is SOC 2 Type II Compliant
When your institutionâs reputation depends on the partners you choose, trust should be supported by evidence. Our marketing and engagement platform is SOC 2 Type II compliant so that you can focus on what matters â reaching your people and growing your brand. Learn more about Connect and see what else it can do.

Sources:
Kovacs, Eduard. âMarquis Data Breach Affects 672,000 Individuals.â SecurityWeek, March 19, 2026. https://www.securityweek.com/marquis-data-breach-affects-672000-individuals/.
American Institute of Certified Public Accountants. âSOC 2ÂŽâReporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy.â AICPA & CIMA. https://www.aicpa-cima.com/cpe-learning/publication/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy.
American Institute of Certified Public Accountants. 2017 Trust Services Criteria (With Revised Points of Focusâ2022). AICPA & CIMA, 2022. https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022.
American Institute of Certified Public Accountants. Privacy Considerations in a SOC 2ÂŽ Examination. AICPA & CIMA. https://www.aicpa-cima.com/resources/download/privacy-considerations-in-a-soc-2-r-examination.
Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency. Interagency Guidance on Third-Party Relationships: Risk Management. https://www.federalreserve.gov/frrs/guidance/interagency-guidance-on-third-party-relationships.htm.
National Credit Union Administration. âNCUAâs Regulations and Guidance.â https://ncua.gov/regulation-supervision/regulatory-compliance-resources/cybersecurity-resources/ncuas-regulations-and-guidance.












