Latest policy on sharing SOC 2 reports

Does anyone know the latest policy on sharing GCP SOC 2 reports? We are a GCP customer, and this is something our customers have asked for. I've heard than an NDA has to be in place, but I didn't know whether that was only an NDA with my company and Google, or and NDA with my company and the customer making the request.

Also, what is the best way to access the SOC 2 bridge letters?

1 REPLY 1

Hello @customerx,

Welcome to Google Cloud Community!

Yes, they were provided to GCP customers under a Non-Disclosure Agreement (NDA) and were typically subject to certain restrictions on sharing. It would be best to contact particularly the GCP Trust Center or directly reach out to Google Cloud support to get the most current and accurate information regarding their policy on sharing SOC 2 reports.

If you are looking for information about SOC 2 reports in GCP, you can access the SOC 2 Type II reports through the GCP console and other resources:

  • Log in to your Google Cloud Console.
  • Navigate to the "Security" section or "Compliance" section of the console.
  • Look for a subsection related to compliance reports or certifications.
  • There, you should find the SOC 2 Type II report and any related documentation.