Service Organization Control 2 - auditing standard for security, availability, and confidentiality of customer data. Like having a security inspection certificate for cloud services.
Cloud providers obtain SOC 2 compliance to prove they meet industry security standards for handling customer data.
SOC 2 is not a cloud service; it’s an independent audit report (AICPA framework) about a service organization’s controls. AWS, Azure, Google Cloud, and OCI can each provide their own SOC 2 reports for their platforms, and customers may pursue SOC 2 for their own SaaS or internal services running on any of these clouds.