THE INDEPENDENT RECORD · AGENTIC AI AS A SERVICE AboutStandardsContact
GAASAGENTIC AI · AS A SERVICE
INDEPENDENT · SINCE 2026
UPDATED DAILY
NO HYPE · NO PAY-TO-PLAY
PER-TASK PRICING NOW STANDARD ● NEW BENCHMARK: 71% TASK COMPLETION ● ENTERPRISE PILOTS UP 4X ● RUNTIME FUNDING ACCELERATES ● "AGENTS ARE THE NEW SEATS" ● MARGINS UNDER PRESSURE ● THE INDEPENDENT RECORD ON GAAS
Trust & Safety

SOC 2 and Beyond: The Certifications GaaS Buyers Actually Require

Short answer: SOC 2 Type II is the table-stakes entry ticket for selling agentic AI as a service to mid-market and enterprise buyers, but it is no longer enough on its own. Buyers are stacking ISO 27001, ISO 42001 (the new AI management standard), HIPAA, PCI DSS, FedRAMP, and increasingly EU AI Act conformity on top of it, and they are asking pointed questions that traditional SaaS audits never anticipated, like "what happens when your agent takes an action no human approved?" This guide breaks down which certifications matter, why, in what order, and where the standard frameworks fall short for autonomous agents.

By J. Okafor · Jun 5, 2026 · 17 min read

Table of Contents

Why Certifications Got Harder When Software Started Acting on Its Own

For two decades, enterprise software procurement followed a comfortable script. A buyer's security team sent a questionnaire, the vendor pointed to a SOC 2 report, legal redlined a DPA, and the deal moved forward. The software was passive, it stored data, displayed dashboards, and waited for a human to click something.

Agentic AI broke that script. When you sell an agent that books travel, issues refunds, files tickets, or moves money without a person in the loop, you are no longer selling a tool. You are selling a coworker who never sleeps and occasionally hallucinates. The security team that used to ask "where is my data stored" now also asks "who is accountable when your agent does something we never authorized?", a question that maps directly to the accountability gap that emerges when no single person controls an agent.

That shift is why certifications have become both more important and more contested in the GaaS market. A certificate is a proxy for trust, and trust is the scarcest commodity in autonomous systems. Buyers can't watch your agent make every decision, so they lean harder on third-party attestations than they ever did for ordinary SaaS. At the same time, the most common certifications were written for a world where software didn't take independent action, which means a clean SOC 2 report can give buyers a false sense of coverage. Understanding that tension is the whole game.

SOC 2: The Entry Ticket, Not the Finish Line

SOC 2 remains the single most requested certification in GaaS procurement, and for good reason. Developed by the AICPA, it audits a vendor's controls against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Most buyers care most about the first one; the others are negotiable depending on the use case.

The distinction that matters is Type I versus Type II. A Type I report attests that your controls are designed correctly at a single point in time. A Type II report attests that those controls actually operated effectively over a period, usually six to twelve months. Enterprise buyers have learned to treat Type I as a polite way of saying "we just started." If you want a procurement team to take you seriously above the SMB tier, you need Type II, full stop. You can read the AICPA's own description of the SOC 2 framework to see how thin the AI-specific guidance still is.

Here is the part GaaS founders underestimate: SOC 2 is scope-defined, and you write the scope. An auditor doesn't independently decide what your agent does, they test the controls you put in front of them. This is a feature and a trap. It means you can earn a legitimate SOC 2 Type II report that says almost nothing about how your agent reasons, what tools it can call, or what guardrails sit between a model's output and a real-world action. Sophisticated buyers know this. The good ones read your report's scope section first and your control list second, and they will notice if "agent action authorization" appears nowhere in either.

So treat SOC 2 as necessary and insufficient. It proves you run a disciplined security program. It does not prove your agent is safe to let loose on production systems, and increasingly, buyers know the difference.

ISO 27001 and ISO 42001: The International Stack

If you sell outside North America, SOC 2 starts to lose its monopoly. European and Asian buyers often prefer ISO/IEC 27001, the international standard for information security management systems (ISMS). Functionally it overlaps heavily with SOC 2, both are about provable, repeatable security governance, but ISO 27001 results in a certification with a defined three-year cycle rather than a point-in-time report, and many global enterprises simply list it as a hard requirement in their vendor onboarding.

The more interesting development is ISO/IEC 42001, published in late 2023 as the first management-system standard specifically for artificial intelligence. This is the one GaaS vendors should be watching closely. Where 27001 governs how you protect information, 42001 governs how you manage AI systems responsibly, risk assessment, impact analysis, data governance for training and inference, transparency, and human oversight. It is, in effect, the first widely recognized standard that was written with autonomous and semi-autonomous systems in mind. The ISO overview of the 42001 standard is worth reading even if you're years away from certifying against it, because it telegraphs exactly what buyers and regulators will eventually demand.

My read: in 2024 and 2025, ISO 42001 is a differentiator, having it signals seriousness and lets you win deals against competitors who only have SOC 2. By 2027 it will likely be table stakes for any agent touching regulated or high-stakes workflows, and it pairs naturally with the emerging agent governance frameworks that enterprises are starting to adopt internally. Vendors who certify early will look prescient. Vendors who wait will look like they got dragged.

Vertical Certifications: HIPAA, PCI DSS, FedRAMP

General-purpose certifications get you in the room. Vertical certifications get you the deal in regulated industries, and they are non-negotiable, not nice-to-haves.

HIPAA governs protected health information in the United States. Strictly speaking, HIPAA has no "certification", there's no government body that hands out a HIPAA badge, but buyers expect a HIPAA-readiness attestation, a signed Business Associate Agreement, and ideally a third-party assessment (often HITRUST, which functions as the de facto certification the industry actually trusts). For any GaaS vendor whose agent reads or writes clinical data, this is the gating requirement, and it connects to a much larger conversation about the compliance burden of running agents in healthcare.

PCI DSS applies the moment your agent touches cardholder data. If your agent processes payments, schedules billing, or even passes through a card number on its way to a processor, you are in PCI scope whether you wanted to be or not. The cleanest architectural move, and the one auditors love, is to design the agent so it never sees raw card data, tokenizing at the edge so PCI scope shrinks to almost nothing.

FedRAMP is the price of admission for selling to US federal agencies. It is expensive, slow, and brutal, authorization can take well over a year and cost hundreds of thousands of dollars, which is precisely why it's a moat. If you earn it, most competitors won't follow. For agentic systems, FedRAMP raises hard questions the program hasn't fully answered yet, particularly around continuous monitoring of a system whose behavior is partly emergent rather than fully specified.

The strategic point across all three: vertical certifications are buyer-segment unlocks, not general trust signals. You pursue them when a specific, high-value market demands them, and you let that market's revenue justify the considerable cost.

The EU AI Act and the Shift From Audit to Conformity

Everything above is voluntary in the sense that no law forces you to get SOC 2. The EU AI Act changes that calculus, because it is regulation, not certification, and it applies based on what your agent does, not where your company sits.

The Act sorts AI systems into risk tiers. Many vertical agents, those involved in hiring, credit, essential services, or critical infrastructure, will land in the "high-risk" category, which triggers mandatory obligations: risk management systems, data governance, human oversight, transparency, logging, and a conformity assessment before the system can be placed on the EU market. The European Commission's official summary of the AI Act lays out the tiers and timelines, and the obligations phase in through 2025 and 2026.

For GaaS vendors this represents a genuine shift in the trust model: from attestation (a third party says you're doing good things) to conformity (you must demonstrate compliance with specific legal requirements or you cannot sell). It also dovetails with ISO 42001, conforming to the ISO standard is widely expected to become evidence of AI Act compliance, which is another reason the two are converging in buyer questionnaires. A fuller treatment of how this regulation reshapes the market belongs in a dedicated discussion of the EU AI Act's impact on agent providers, but the headline for procurement is simple: for high-risk agents, EU compliance is becoming a legal gate, not a sales differentiator.

What the Standard Frameworks Miss About Agents

This is where the information gain lives, because the honest answer is that none of the frameworks above were designed for software that acts autonomously. They were built for systems that store, transmit, and process data, not systems that decide and execute.

Consider what a typical SOC 2 audit does not test:

The practical consequence is that a clean certification stack and a safe agent are two different things, and the gap between them is where incidents happen. The smartest GaaS vendors are getting ahead of this by publishing supplementary documentation, agent-specific threat models, kill-switch designs, scoped-permission architectures, and audit-log schemas, that goes beyond what any auditor asks for. That voluntary transparency is quietly becoming a competitive advantage, and it's the seed of what may eventually become a purpose-built trust certification for agent vendors.

How Buyers Actually Evaluate the Stack

In real procurement, certifications are necessary but they are the floor of the evaluation, not the ceiling. Here is the order I see sophisticated buyers actually work through:

  1. Gate check. Do you have SOC 2 Type II? No report, no meeting. This filters out the unserious before anyone spends time.
  2. Scope scrutiny. They read the report's scope and control list looking for agent-specific controls. A SOC 2 that covers your web app but not your agent's action layer reads as a red flag.
  3. Vertical match. If they're regulated, they check for HIPAA/HITRUST, PCI, or FedRAMP as appropriate. This is binary, you have it or you don't sell to them.
  4. Custom questionnaire. This is where the real work happens. Expect dozens of agent-specific questions about authorization, logging, data retention, model providers, and incident response that no certification answers. Building a thoughtful response to these is so consequential that buyers are now constructing dedicated security questionnaires for buying agents.
  5. Architecture deep-dive. For large deals, their security team wants a live conversation about your agent's permission model, sandboxing, and emergency stops, the things certificates gesture at but don't prove.

The takeaway for vendors: collecting certificates is the easy 40% of trust. The hard 60% is everything the certificates don't cover, and that's where deals are actually won or lost.

A Sequencing Plan for GaaS Vendors

If you're building a GaaS company and wondering where to spend limited compliance budget, here is a defensible sequence:

Running underneath all four stages is the agent-specific documentation the frameworks ignore, threat models, governance committees, and the human-accountable-owner requirement for every agent that mature buyers increasingly expect. That layer is what separates a vendor who merely passes audits from one buyers actually trust with autonomous access to their systems.

Insights Most People Overlook

A SOC 2 report can be technically clean and substantively meaningless for an agent. Because the vendor scopes the audit, it's entirely possible to hold a legitimate Type II report that tests your authentication and backups while saying nothing about your agent's ability to take unauthorized actions. The certificate is real; the relevant coverage may be zero. Buyers who only check for the badge, not the scope, are trusting a document that wasn't designed to answer their actual question.

ISO 42001 will eat part of SOC 2's lunch in agentic deals. Most coverage treats these as complementary, and they are, but for autonomous systems specifically, 42001 addresses the risks buyers care about (oversight, transparency, AI-specific risk management) that SOC 2 structurally cannot. Vendors who frame 42001 as "nice extra" are misreading where buyer attention is heading.

The most valuable trust artifact in 2025 isn't a certificate at all, it's a published threat model. Certifications are commoditized; everyone in a serious deal has SOC 2. What differentiates is voluntary transparency about how your agent can fail and what stops it. A clear, honest document describing your agent's permission boundaries, kill switches, and failure modes does more to win a skeptical security team than a wall of logos.

Vertical certifications are moats precisely because they're miserable. FedRAMP's cost and pain aren't a bug to route around, they're the reason it protects margin. If a certification were cheap and fast, it wouldn't keep competitors out. Founders who complain about how hard FedRAMP is are missing that the difficulty is the entire strategic value.

Certification scope creep is coming, and early movers set the template. Auditors will eventually develop agent-specific control frameworks, but right now there's a vacuum. Vendors defining their own rigorous agent controls today are effectively writing the standard others will be measured against tomorrow, the same dynamic that played out when cloud-specific SOC 2 controls emerged a decade ago.

Frequently Asked Questions

Is SOC 2 legally required to sell agentic AI? No. SOC 2 is a voluntary attestation, not a law. But in practice, mid-market and enterprise buyers treat it as mandatory, so it functions as a commercial requirement even though no regulator demands it. The EU AI Act, by contrast, is legally binding for high-risk systems sold into the EU.

What's the difference between SOC 2 and ISO 27001 for an agent vendor? They cover similar ground, disciplined, provable security governance, but SOC 2 produces a point-in-time-period attestation report favored in North America, while ISO 27001 produces a certification on a three-year cycle favored internationally. Many global buyers want both. Neither is AI-specific, which is why ISO 42001 increasingly sits alongside them.

Do I need HIPAA certification if my agent only occasionally touches health data? There's no formal HIPAA certification, but if your agent reads or writes protected health information at all, you need HIPAA readiness, a signed Business Associate Agreement, and almost certainly a HITRUST assessment to satisfy healthcare buyers. "Occasionally" doesn't reduce your obligation, any access pulls you into scope.

Can I reduce PCI DSS scope for a payment-handling agent? Yes, and you should. The standard approach is to architect the agent so it never sees raw cardholder data, tokenize at the edge and pass tokens, not card numbers. Done well, this shrinks your PCI scope dramatically and simplifies the audit.

How does ISO 42001 relate to the EU AI Act? They're complementary. ISO 42001 is a voluntary management-system standard for responsible AI; the EU AI Act is binding regulation. Conforming to 42001 is widely expected to serve as evidence toward AI Act compliance, which is a major reason both are appearing together in buyer requirements.

What agent-specific controls should I document beyond standard certifications? At minimum: runtime action authorization, scoped least-privilege permissions for the agent's tools, decision-level audit logging, a kill switch, data retention policy for agent memory, and a named human accountable owner. These are exactly the gaps standard frameworks leave open, and documenting them is what differentiates serious vendors.

Conclusion

Certifications in the GaaS market are best understood as layers, not a single badge. SOC 2 Type II is the entry ticket that gets you into enterprise conversations. ISO 27001 extends that trust internationally, and ISO 42001 is rapidly becoming the AI-specific standard that buyers of autonomous systems will soon expect by default. Vertical certifications, HIPAA, PCI DSS, FedRAMP, are buyer-segment unlocks you pursue when a specific market's revenue justifies the cost. And the EU AI Act marks the shift from voluntary attestation to mandatory conformity for high-risk agents.

But the deeper lesson is that every one of these frameworks was built for software that doesn't act on its own. The gap between a clean certification stack and a genuinely safe agent is real, and it's where incidents, and lost deals, happen. The vendors winning the trust war aren't just collecting logos. They're documenting the things certificates don't cover: how their agent is authorized, scoped, logged, and stopped. In a market where buyers can't watch every decision an agent makes, that voluntary transparency is becoming the most valuable certification of all, even though no one has figured out how to hand it a badge yet.

References

More in Trust & Safety