If someone on your team recently mentioned SOC 2, or a potential customer asked if you're SOC 2 compliant, you've probably realized there's a lot more to it than just a certificate on your website.
SOC 2 (Service Organization Control 2) is a security framework that shows your customers and partners that you take data protection seriously. It's become a standard requirement for B2B SaaS companies, especially when selling to enterprise clients. And one of the areas that gets the most scrutiny during an audit? How you manage the devices your employees use every day.
Here's what you need to have in order on the device management side before you go into a SOC 2 audit, or before you start working toward one.
SOC 2 is basically a third-party stamp of approval that says: "This company has controls in place to protect customer data." Many enterprise buyers require it before signing a contract.
There are two types:
Device management touches several of the core "trust service criteria" that SOC 2 auditors look at, specifically around security, availability, and confidentiality.
An MDM is software that lets you manage, monitor, and control company devices from one place. If you don't have one, you have no way to enforce any of the requirements below, and an auditor will flag it immediately.
Every Mac, iPhone, and iPad used for work should be enrolled. Personally-owned devices (called BYOD) used for work email or Slack need a policy too, even if they're not fully enrolled.
If a laptop gets lost or stolen, encryption is what keeps company and customer data from walking out the door with it.
On Macs, this is called FileVault. On iPhones and iPads, encryption is on by default, but your MDM should confirm it's actually enabled and hasn't been turned off.
SOC 2 auditors will ask for evidence that encryption is enforced across your fleet, not just recommended.
"We tell employees to use strong passwords" isn't enough. You need to be able to prove it's enforced.
Your MDM should push minimum requirements:
Outdated software is one of the most common ways attackers get in. SOC 2 requires that you have a process for keeping devices patched and up to date.
Your MDM should let you see which devices are running outdated software and push updates, or at minimum alert users and enforce a deadline.
When an employee leaves, their device needs to be wiped whether they return it or not. SOC 2 auditors will want to know you have the ability to remotely wipe a device if it's lost, stolen, or an employee is offboarded.
Without an MDM, this isn't possible. With one, it's a button click.
You need to know exactly what devices exist in your company, who has them, and what state they're in. This sounds simple, but for fast-growing companies, it's surprisingly easy to lose track.
A good MDM gives you a live inventory: serial numbers, OS versions, enrollment status, last check-in. Auditors will ask for this list.
When someone leaves your company, what happens to their device access? Their email? Their app logins?
SOC 2 requires a documented offboarding process that includes:
This is one of the most common gaps we see in growing companies. It works fine with 10 people. By 40, it's a mess.
Are employees installing random apps on company laptops? Are they using unauthorized tools that could expose company data?
SOC 2 requires that you have visibility into what's installed and a policy around it. Your MDM should give you a software inventory and the ability to block or approve applications.
This one is newer, but auditors are starting to pay attention. If your employees are using AI tools like ChatGPT, Copilot, or Claude for work, you need a policy that addresses:
As AI becomes part of everyday work, device and data policies that don't address it are going to stick out in an audit.
SOC 2 compliance is a signal to your customers that you've built real infrastructure around protecting their data. Device management is one of the most concrete, visible parts of that.
If you have the right MDM in place and someone actively managing it, most of the items on this list are either automatic or easy to enforce. The hard part is doing it before your first audit, not scrambling through it afterward.
If you're not sure where your company stands, we offer a free MDM health check that gives you a clear picture of what's covered and what's not. Reach out if you're interested.
Phalanx Management helps growing tech companies manage their devices, stay secure, and stay compliant. Based in Colorado, we work with SaaS and tech teams who are ready to take IT seriously without hiring a full internal team.