Android and iOS

What a SOC 2 report says about a RASP supplier

OWASP, secure development and the evidence behind controls.

Standards and evidence1 min readEditorial methods

A SOC 2 report provides information about a defined system and period. Its existence does not mean your mobile application passed an independent security test.

Evaluation approach

Check whether the product used falls within the reported system. Review controls, exceptions, subservice organizations and customer responsibilities. A logo is not a substitute for the report.

Application example

A cloud telemetry service may be covered while a customer-hosted component has different responsibilities. Carry customer duties such as API-key management and access review into the operating plan.

Limits and considerations

A SOC 2 report does not demonstrate that an SDK blocks every mobile attack. Read the report type and covered period carefully.

Checks and decisions

  • Match product and report scope
  • Review exceptions
  • Assign customer controls

Use supplier assurance alongside product trials. Organizational control assurance and application protection effectiveness require different evidence.

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.