Key takeaways:
- SOC 2 compliance demonstrates that an organization has strong controls in place for protecting its customers’ data.
- SOC 2 is especially important for SaaS companies that regularly store and/or process sensitive information.
- SOC 2 Type II compliance provides stronger assurance than Type I.
- Even though SOC 2 compliance isn’t required by law, many schools and tutoring organizations consider it when vetting and choosing a virtual classroom platform.
What is SOC 2 compliance?
Systems and Organization Controls 2, or SOC 2, is a security framework developed by the American Institute of Certified Public Accountants (AICPA). Unlike most trust and security frameworks, SOC 2 doesn’t relate to a product’s features. Rather, it evaluates how a company protects its customers’ data in its internal systems, policies, and day-to-day operations.
In practice, this means that a company that demonstrates SOC 2 compliance has implemented controls that were specifically designed to keep customer information secure, available, and confidential.
Although people will often refer to “SOC 2 certification,” that’s not technically the correct term, as organizations can’t just “become” certified. In reality, an independent auditor has to conduct a SOC 2 audit and issue a report describing whether or not the organization’s controls meet the SOC 2 Trust Services Criteria.
Today, SOC 2 compliance is especially relevant to SaaS companies, including online tutoring platforms. The independent validation of SOC 2 compliance offers SaaS customers and EdTech buyers an unprecedented level of confidence in the company’s security.
What are the SOC 2 requirements?
While most compliance frameworks prescribe a single, rigid checklist that every part of an organization has to follow, SOC 2 doesn’t. Instead, it centers five Trust Services Criteria that organizations need to adopt according to the services they provide:
- Security: The only mandatory Trust Services Criterion. Assesses whether an organization has protective systems in place to prevent unauthorized access to customers’ data.
- Availability: Looks at whether or not a system is accessible and operational when a customer needs it to be.
- Processing integrity: Considers whether the systems within an organization process users’ information accurately and completely, in a timely manner.
- Confidentiality: Focuses on protecting users’ sensitive information from unauthorized disclosure.
- Privacy: Covers how consistently organizations collect, use, retain, disclose, and dispose of personal information, from the start to the end of its lifecycle.
Not every SOC 2 report includes all five criteria, but Security is always a mandatory requirement. The remaining four criteria are included when and where they’re relevant to the services that an organization provides.
Often, the most common source of confusion regarding SOC 2 compliance isn’t these criteria in and of themselves, but rather the two different types. These are namely SOC 2 Type I vs. Type II.
Both reports have the same primary purpose: to evaluate a company’s control systems. The difference comes down to the specific questions that they aim to answer:
Between the two, SOC 2 Type II is generally considered the gold standard. Because the auditing process examines evidence that’s collected over an extended period of time, it offers much stronger assurance that security practices are followed consistently than what a snapshot in time would.
How does SOC 2 apply to online tutoring and education?

Although security is undeniably important in all industries, it’s especially important for software companies that store customer information online. That’s why SOC 2 for SaaS has become an unspoken industry benchmark.
For online tutoring platforms, specifically, it’s often the case that schools will entrust them with sensitive data such as lesson recordings, student information, attendance records, learning resources, and educational transcripts. Demonstrably strong security practices are essential for proving that an organization responsibly handles its customers’ information.
Pencil Spaces is SOC 2 Type II compliant, so it gives schools, tutoring organizations, and independent educators the confidence that the platform has been independently assessed against recognised the highest industry standards. Alongside FERPA, COPPA, GDPR, and HIPAA compliance, SOC 2 Type II reflects Pencil Spaces' ongoing commitment to protecting student and customer data.
SOC 2 vs ISO 27001 vs FERPA vs COPPA
These terms are often mentioned together, but it’s important to emphasize that they serve very different purposes:
For many organizations, these frameworks and regulations work together. An online tutoring platform may pursue SOC 2 compliance to show how strong their security practices are, yet they’ll likely also ensure compliance with FERPA, COPPA, and the GDPR where those laws apply.
Frequently asked questions
Is SOC 2 required by law?
No, SOC 2 isn’t a legal requirement. However, many organizations (e.g., schools, enterprises, tutoring companies, etc.) expect software providers to demonstrate strong security practices. This is why SOC 2 compliance is viewed as such an important trust signal for many SaaS companies.
What is the difference between SOC 2 Type I vs. Type II?
A SOC 2 Type I report evaluates whether or not a company has security controls at a singular specific point in time. A SOC 2 Type II report provides a much higher level of assurance, as it assesses whether those same controls operate effectively over an extended period of time.
Do online tutoring platforms need SOC 2?
Not every tutoring platform needs to be SOC 2 audited, but it’s increasingly becoming a baseline. Since a platform with SOC 2 Type II compliance is considered to have thorough security controls, it’d be a strong contender for schools, colleges, universities, or large tutoring companies that regularly deal with sensitive student information.
Pencil Spaces is SOC 2 Type II compliant and built to help schools, tutoring organizations, and educators protect their students’ data with the utmost confidence. Read our Trust & Security page to learn more, or book a free demo to see the platform in action.

.png)








