SOC 2 RFP Software (2026)
Compare RFP and questionnaire platforms with publicly documented SOC 2 assurance and the controls needed for governed response work.
How to evaluate this shortlist
A SOC 2 report can provide procurement evidence about a vendor's controls, but the marketing label alone does not reveal the report type, period, covered entity, system scope, exceptions, or bridge-letter status. Buyers should request the current report under NDA and review it with their own risk criteria.
The directory tag reflects current public vendor claims, not an independent audit by RFP AI Hub. Separately assess data flow, subprocessors, encryption, access controls, audit logs, retention, incident response, and whether customer content is used by external AI providers.
What to verify in your shortlist
- Check 1SOC 2 type, period, legal entity, system scope, and bridge coverage
- Check 2Exceptions, subprocessors, AI data handling, retention, and incidents
- Check 3SSO, SCIM, RBAC, audit logs, encryption, and residency options
Use the live search and filters below to narrow the directory, then open each profile for pricing, limitations, security evidence, and reviewed sources.
Explore matching tools