Share via

Use SOC2 as proof for a client

Yiz Segall 40 Reputation points
2025-08-13T08:43:53.79+00:00

Hi,

I need to prove to a client that my app on Azure is SOC2 and/or ISO compliant. I know that there are certificates, but it seems that I can't use them.

Is there something I can show a client?

Azure App Service
Azure App Service

Azure App Service is a service used to create and deploy scalable, mission-critical web apps.


1 answer

Sort by: Most helpful
  1. Bhargavi Naragani 7,940 Reputation points Microsoft External Staff Moderator
    2025-08-13T12:00:32.5666667+00:00

    Yiz Segall, you’re correct, the SOC 2 and ISO audit reports you download from the Microsoft Service Trust Portal are marked Microsoft Confidential, which means they can’t be redistributed. This restriction is part of Microsoft’s non-disclosure agreement (NDA) terms for accessing those documents.

    However, there are a couple of fully supported ways you can still prove compliance to your own client:

    Have your client access the reports directly

    • If they have a Microsoft account (any Azure, Microsoft 365, or free personal account works), they can sign in to the Service Trust Portal themselves and download the same SOC 2 and ISO audit reports you see.
    • This way, you are not redistributing confidential files, you are simply guiding them to the official source.

    Use Microsoft’s publicly shareable compliance summaries

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.