Glossary
SOC 2
Learn what SOC 2 compliance means and how it relates to commercial HVAC and smart building solutions.
Quick Facts
- Products
- Smart Building Solutions • Cybersecurity
- Topics
- Smart Buildings
Selecting a language changes the language and content on the Trane site.
Trane ComfortSite is an extranet site designed to save you time. With your secure login, you can:
This is the login for Trane® Connect™ and other Trane® commercial applications. Trane® Connect™ is our secure, cloud-based customer portal to access your building systems to remotely monitor and manage building systems, and conduct routine maintenance.
Latin America
Europe
Asia Pacific
Glossary
Learn what SOC 2 compliance means and how it relates to commercial HVAC and smart building solutions.
Quick Facts
SOC 2 (System and Organization Controls 2) is a compliance standard that specifies how organizations should manage customer data and related systems. The SOC 2 standards are based on the Trust Services Criteria (TSC) set forth in TSP section 100 2017, a set of principles and controls developed by the American Institute of Certified Public Accountants (AICPA). The five AICPA’s 2017 Trust Services Criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy (inclusive of March 2020 updates).
SOC 2 standards are designed for service organizations, such as cloud providers, software as a service (SaaS) vendors, and other organizations that provide web-based services. While some may refer to SOC 2 certification, it is more accurate to call the process of gaining compliance a SOC 2 attestation. SOC 2 audits are conducted by licensed CPAs based on standards set by the AICPA, but there's no certifying body or official certification. To get a SOC 2 report, you must undergo an audit by a third-party auditor, either a CPA or a firm certified by the American Institute of Certified Public Accountants (AICPA), who will evaluate your security posture to determine if your policies, processes, and controls meet SOC 2 compliance requirements.
SOC 2 audits are based on five Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy, which guide how a company must manage its systems, data, and operations to meet modern security expectations. Only the security criterion is mandatory, while the other four are optional and selected based on your organization's services and commitments.
The AICPA TSC provide guidelines to structure each audit and offer focus points to help companies implement controls. Every business will need to decide which controls they'll need to bring their systems into compliance with SOC 2 standards.
Integrating smart HVAC solutions into your facility should never introduce cyber vulnerabilities. Prioritizing a vendor that understands and adheres to SOC 2 is crucial for several reasons:
Resources for SOC 2
Trane Commercial HVAC is committed to providing industry-leading, secure building controls. By ensuring your HVAC systems adhere to stringent cybersecurity and data protection frameworks, you can confidently optimize your building's performance while keeping your digital infrastructure safe. Contact your local Trane representative to learn more.