Alternatives to Vendor SOC Reports: What to Review to Manage Risk
Most of us know by now how useful it is to review a vendor’s SOC report when doing third-party due diligence. But what if your vendor doesn't have a SOC report? If a vendor doesn’t have a SOC report, that may be considered a red flag, however, in some cases, the vendor can’t provide a SOC report because they’re costly to obtain or the vendor is newly established.