What SOC 2 Type II Certification Means (and Doesn’t Cover) — ABA

Source: American Bar Association — “What SOC 2 Type II Certification Means”

Publisher: American Bar Association
Date Published: 2014 (Law Technology Today)
Relevant To: SB 1516 compliance analysis — rebuts Axon’s SOC 2 defense
Verification Status: Verified

Notes: Explains that SOC 2 Type II audits whether a vendor’s internal controls operate as the vendor itself describes them, over a 6–12 month period. The Privacy principle requires only that data be handled per the vendor’s own privacy notice — not per state law. SOC 2 does not require end-to-end encryption and does not audit compliance with Oregon SB 1587 or SB 1516. This directly rebuts any argument that Axon’s SOC 2 certification satisfies the Oregon State CISO’s Feb. 14, 2026 finding (cataloged separately) that Axon lacks true E2EE architecture. Useful explainer for anticipating and countering a likely vendor talking point. Migrated from the existing Bend Surveillance Oversight source library.