
{"id":1520,"date":"2011-02-15T00:00:00","date_gmt":"2011-02-15T00:00:00","guid":{"rendered":"http:\/\/otava.test\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/"},"modified":"2011-02-15T00:00:00","modified_gmt":"2011-02-15T00:00:00","slug":"sas-70-ssae-16-soc-2-and-soc-3-data-center-standards","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/","title":{"rendered":"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards"},"content":{"rendered":"<p>I just got off the phone with our data center auditors, UHY LLP, with an update on what\u2019s going on in the world of SAS 70, SSAE 16, SOC 2 and SOC 3 auditing standards for data centers.<\/p>\n<p><a title=\"SAS 70 data center\" href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/soc-1-2-3-compliant-cloud\/\">SAS 70<\/a> (Statement on Auditing Standards No. 70) was around for nearly 20 years until it was replaced. First released in 1992, it was the gold standard for data center users to assure that their data center is secure and operating under proper control systems. The problem with the SAS 70 standard according to the American Institute of CPAs (AICPA), is that SAS 70 was never designed to be used by service organizations that offer <a title=\"SAS 70 Colocation\" href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/colocation\/\">colocation<\/a>, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/professional-services\/remote-management-and-monitoring-services\/\" target=\"_blank\" rel=\"noopener noreferrer\">managed servers<\/a> or <a title=\"SAS 70 Cloud Hosting\" href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/\">cloud hosting services<\/a> in this manner. It was focused on internal controls over financial reporting.<\/p>\n<p>A SAS 70 audit only verified that the controls and processes that the data center operator has in place were followed. There is no minimum bar that the data center operator has to achieve and no benchmark to hold data center operators accountable to. A data center with strong controls and processes can claim the same level of audit as a data center operator with weak controls and systems. The only way a user can tell the difference is to read through the detailed audit report.<\/p>\n<p>A prevalent misunderstanding about SAS 70 is that after completing a SAS 70 audit, a data center or other service organization becomes \u201cSAS 70 Certified.\u201d No such official certification exists for SAS 70, so many service providers that have survived a SAS-70 audit have created their own logo, indicating the need for such certification by outside auditors.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Enter_SSAE_16_SOC_2_and_SOC_3_auditing_standards\"><\/span><strong>Enter SSAE 16, SOC 2 and SOC 3 auditing standards. <\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div style=\"width: 550px; background-color: #1f89c5; color: white; padding: 10px; margin: 20px 0;\">\n<p style=\"color: white; text-align: left; padding: 10px;\"><strong style=\"color: white;\">Update December 2017:<\/strong>\u00a0SSAE 16 has recently been replaced with SSAE 18. For more information about the new standard and resulting SOC 1 report, see our post by guest blogger David Barton of UHY LLP: <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/ssae-18-vs-ssae-16-key-differences-in-the-new-soc-1-standard\/\" target=\"_blank\" rel=\"noopener noreferrer\">SSAE 18 vs SSAE 16: Key differences in the new SOC 1 standard<\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/soc-1-2-3-compliant-cloud\/\">SSAE 16<\/a> (Statements on Standards for Attestation Engagements No. 16) is the next generation of AICPA standards for reporting on controls at service organizations (including data centers) in the United States. SSAE 16 goes beyond SAS 70 by requiring the auditor to obtain a written assertion from management regarding the design and operating effectiveness of the controls being reviewed. SSAE 16 also provides better alignment with the international audit standard ISAE 3402.<\/p>\n<p><strong>New Reporting Options<\/strong><\/p>\n<p>Under the new AICPA reporting standards, an audit that is conducted under SSAE 16 will result in a Service Organization Control (SOC) 1 report. These reports are still focused on controls relevant to internal control over financial reporting. In essence, a SOC 1 report will be the form of reporting once the SSAE 16 audit is complete.<\/p>\n<p>As with the old SAS 70, SOC 1 reports will be available as Type 1 or Type 2 reports. Type 1 reports present the auditors\u2019 opinion regarding the accuracy and completeness of management\u2019s description of the system or service as well as the suitability of the design of controls as of a specific date. A Type 2 SOC 1 report includes the Type 1 criteria <em>AND<\/em> audits the operating effectiveness of the controls throughout a declared time period, generally between six months and one year. Like SAS 70, there is no official SSAE 16 or SOC 1 certification.<\/p>\n<p><a href=\"https:\/\/www.onlinetech.com\/soc-2-hosting-soc-3-hosting\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 2<\/a> and <a href=\"https:\/\/www.onlinetech.com\/soc-3-hosting\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 3<\/a> provide much more stringent audit requirements with a stronger set of controls and requirements specifically designed around data center service organizations. <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/soc-1-2-3-compliant-cloud\/\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 2<\/a> and SOC 3 provide a standard benchmark by which two data center audits can be compared against the same set of criteria. In contrast to an SSAE-16 engagement, where the data center operator defines the criteria for an audit, the <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/what-is-a-service-organization-control-soc-2-report\/\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 2 report<\/a> uses specifically pre-defined control criteria related to 1) security, 2) availability, 3) processing integrity, 4) confidentiality or 5) privacy of a system and its information.<\/p>\n<p><strong>SOC 2 provides what was missing in the SAS 70 and SSAE 16<\/strong> &#8211; a standard benchmark by which two data center audit reports can be compared and the reader can be assured that the same set of criteria was used to evaluate each.<\/p>\n<p>SOC 3 reports provide the same level of assurance about controls over security, availability, processing integrity, confidentiality and\/or privacy as a SOC 2 report, but the report is intended for general release and does not contain the detailed description of the testing performed by the auditor, but rather, a summary opinion regarding the effectiveness of the controls in place at the data center or service organization.<\/p>\n<p><strong>SOC 3 <\/strong>also meets the demand that high tier data center operators have been screaming for \u2013 <strong>Certification!<\/strong> Once the auditor is assured that the data center operator has achieved the trust services criteria, the company can display the SOC 3: SysTrust for Service Organizations seal.<\/p>\n<figure id=\"attachment_2038\" aria-describedby=\"caption-attachment-2038\" style=\"width: 240px\" class=\"wp-caption alignright\"><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/soc-3-certified\/\" rel=\"attachment wp-att-2038\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2038 \" title=\"SOC 3 Certified\" src=\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg\" alt=\"SOC 3 Certified Data Center\" width=\"240\" height=\"240\" \/><\/a><figcaption id=\"caption-attachment-2038\" class=\"wp-caption-text\">SOC 3 Certification<\/figcaption><\/figure>\n<p>While this seal still looks like it was designed by a CPA, it\u2019s a huge step in the right direction. (I\u2019m guessing that unless the AICPA adds some marketing flair to the certification logo, companies will create their own logos that clients and users can more readily understand.) Now, high quality colocation, cloud hosting and <a title=\"SaaS Hosting\" href=\"https:\/\/otavawebsite.wpengine.com\/about\/resources\/case-studies\/\">Software-as-a-Service <\/a>(SaaS) providers have a standard and certification process they can adhere to. SOC 2 and SOC 3 provides data center users a high level of assurance that their data center is secure, highly available and operating under a consistent set of high integrity processes.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"SOC_2_and_SOC_3_%E2%80%93_Welcome_Standards_to_the_Data_Center_Industry\"><\/span><strong>SOC 2 and SOC 3 \u2013 Welcome Standards to the Data Center Industry<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>SOC 2 and SOC 3 are welcome standards to our industry. They will raise the bar for some, and allow others to shine under the stringent processes they are already running under. Users will get what they\u2019ve been looking for \u2013 a standard benchmark against which to compare data center operators.<\/p>\n<p>High quality <a title=\"SAS 70 Colocation\" href=\"https:\/\/www.onlinetech.com\/colocation\/overview\">colocation<\/a>, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/private-cloud\/\">managed servers<\/a>, cloud hosting and SaaS providers will get what they\u2019ve been looking for \u2013 a certification process that provides their users a high level of assurance about the quality of their data center security, availability and process integrity.<\/p>\n<p>You can read more detail on SSAE 16, SOC-2 and SOC-3 in the guest blog posted by our auditor, David Barton of UHY LLC &#8211; <a title=\"SSAE 16 and SAS 70\" href=\"https:\/\/otavawebsite.wpengine.com\/blog\/socs-and-sass-the-new-standards-for-service-organization-controls-reporting\/\">SOCs and SASs: The New Standards for Service Organization Controls Reporting<\/a>.<\/p>\n<p><strong>UPDATE (3\/27\/2011) <\/strong>&#8211; I recently read a white paper from a firm in Missouri that positions SOC-2 and SOC-3 as part of SSAE-16. That wasn&#8217;t my understanding, and when I checked with our auditors, here is what they told me:<\/p>\n<p>SOC 2 and SOC 3 reports are not part of SSAE 16. SOC 2 and SOC 3 are conducted under AT 101. There is no SSAE for these reports. The chart below comes from the AICPA brochure regarding the new reporting standards:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17522 size-full\" title=\"SSAE 16 SOC 2 &amp; SOC 3 data centers\" src=\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-new-standards-and-options-table-1.jpg\" alt=\"SSAE 16 vs SOC 2 vs SOC 3 data center standards\" width=\"601\" height=\"499\" \/><\/p>\n<p>The entire report is available here:<\/p>\n<p><a href=\"https:\/\/www.aicpa.org\/InterestAreas\/InformationTechnology\/Resources\/TrustServices\/DownloadableDocuments\/10957-378%20SOC%20Whitepaper.pdf\">https:\/\/www.aicpa.org\/InterestAreas\/InformationTechnology\/Resources\/TrustServices\/DownloadableDocuments\/10957-378%20SOC%20Whitepaper.pdf<\/a><\/p>\n<p>Hope this helps.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Additional_resources\"><\/span>Additional resources<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Get more information about SAS 70, SSAE 16 and SOC from the following:<\/p>\n<p><em> <a href=\"https:\/\/otavawebsite.wpengine.com\/reference\/sas-70-ssae-16-and-soc-comparison\/\"> SAS 70, SSAE 16, and SOC comparison:<\/a><\/em><br \/>\nWhat\u2019s the difference between SAS 70, SSAE 16 and SOC? SAS 70 is the old standard that was never designed for certain service organizations that offer colocation&#8230; <a href=\"https:\/\/otavawebsite.wpengine.com\/reference\/sas-70-ssae-16-and-soc-comparison\/\">(Continue Reading)<\/a><\/p>\n<p><em> <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/soc-1-soc-2-soc-3-report-comparison\/\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 1, SOC 2, SOC 3 report comparison:<\/a> <\/em><br \/>\nIn April 2010, the AICPA (American Institute of Certified Public Accountants) announced the replacement of SAS 70 by a new and refined auditing standard, the Statement on Standards for Attestation Engagements or SSAE 16. While SAS 70 was originally&#8230;<a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/soc-1-soc-2-soc-3-report-comparison\/\" target=\"_blank\" rel=\"noopener noreferrer\">(Continue Reading)<\/a><\/p>\n<p><em><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/what-is-a-service-organization-control-soc-2-report\/\" target=\"_blank\" rel=\"noopener noreferrer\">What is a Service Organization Control (SOC) 2 Report?\u00a0<\/a><\/em><br \/>\nIntroduced in 2011, Service Organization Control (SOC) reports are becoming more and more popular in data security and compliance discussions\u00a0with every passing year, especially <a href=\"https:\/\/www.onlinetech.com\/soc-2-hosting-soc-3-hosting\" target=\"_blank\" rel=\"noopener noreferrer\">SOC 2<\/a>\u00a0&#8230;\u00a0<a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/what-is-a-service-organization-control-soc-2-report\/\" target=\"_blank\" rel=\"noopener noreferrer\">(Continue Reading)<\/a><\/p>\n<div style=\"width: 550px; background-color: #1f89c5; color: white; padding: 10px; margin: 20px 0;\">\n<p style=\"color: white; text-align: left; padding: 10px;\"><strong style=\"color: white;\">Update:<\/strong> SAS 70 reports only on controls related to financial reporting. If you need assurance of controls directly related to data centers, including privacy, security and availability, look for a <a style=\"color: white; text-decoration: underline;\" href=\"https:\/\/www.onlinetech.com\/soc-2-hosting-soc-3-hosting\">SOC 2 report<\/a>.<br \/>\nSAS 70 was replaced by SSAE 16 in June 2011.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>I just got off the phone with our data center auditors, UHY LLP, with an update on what\u2019s going on in the world of SAS 70, SSAE 16, SOC 2 and SOC 3 auditing standards for data centers. SAS 70 (Statement on Auditing Standards No. 70) was around for nearly 20 years until it was replaced. First released in 1992, it was the gold standard for data center users to assure that their data center is secure and operating under proper control systems. The problem with the SAS 70 standard according to the American Institute of CPAs (AICPA), is that SAS 70 was never designed to be used by service organizations that offer colocation, managed servers or cloud hosting services in this manner. It was focused on internal controls over financial reporting. A SAS 70 audit only verified that the controls and processes that the data center operator has in place were followed. There is no minimum bar that the data center operator has to achieve and no benchmark to hold data center operators accountable to. A data center with strong controls and processes can claim the same level of audit as a data center operator with weak controls and&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-1520","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Security<\/title>\n<meta name=\"description\" content=\"These standards and processes assure the quality of the data center security, availability and process integrity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards\" \/>\n<meta property=\"og:description\" content=\"These standards and processes assure the quality of the data center security, availability and process integrity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2011-02-15T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards\",\"datePublished\":\"2011-02-15T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\"},\"wordCount\":1265,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\",\"url\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\",\"name\":\"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Security\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg\",\"datePublished\":\"2011-02-15T00:00:00+00:00\",\"description\":\"These standards and processes assure the quality of the data center security, availability and process integrity.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Security","description":"These standards and processes assure the quality of the data center security, availability and process integrity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/","og_locale":"en_US","og_type":"article","og_title":"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards","og_description":"These standards and processes assure the quality of the data center security, availability and process integrity.","og_url":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/","og_site_name":"OTAVA","article_published_time":"2011-02-15T00:00:00+00:00","og_image":[{"url":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg","type":"","width":"","height":""}],"author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards","datePublished":"2011-02-15T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/"},"wordCount":1265,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"image":{"@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage"},"thumbnailUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg","inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/","url":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/","name":"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Security","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage"},"image":{"@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage"},"thumbnailUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg","datePublished":"2011-02-15T00:00:00+00:00","description":"These standards and processes assure the quality of the data center security, availability and process integrity.","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#primaryimage","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/SOC-3-Certified.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/sas-70-ssae-16-soc-2-and-soc-3-data-center-standards\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"SAS 70, SSAE 16, SOC 2 and SOC 3 Data Center Standards"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/1520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=1520"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/1520\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=1520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=1520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=1520"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=1520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}