SOC 2 Compliant Hotel PMS: A Buyer’s Due-Diligence Guide

Choosing a SOC 2 compliant hotel PMS? Stayntouch meets SOC 2, PCI DSS, and GDPR standards. Get the due-diligence checklist and pick with confidence.

SOC 2 Compliant Hotel PMS: A Buyer’s Due-Diligence Guide

Written by: Kelly Campbell, Vice President of Marketing, Stayntouch

Key Takeaways

  • SOC 2 is an attestation report issued by a licensed CPA firm. Buyers must request the actual report to verify compliance.
  • A hotel PMS is uniquely sensitive because it stores guest PII and connects to door locks, POS, payments, and CRM systems.
  • SOC 2 Type II reports are the standard for enterprise buyers because they test whether controls operated effectively over time.
  • Buyers should request the full SOC 2 Type II report, confirm the PMS application is in scope, review exceptions, and ask about subprocessors and penetration tests.
  • Stayntouch holds SOC 2 Type I, PCI DSS Level 1 for Stayntouch Pay, GDPR compliance, ISO 27001/27018 certification, and AWS Private VPC infrastructure with scoped OAuth integrations.

Request Stayntouch's SOC 2 Report

Why a Hotel PMS Is a Uniquely Sensitive System

A property management system (PMS) is the core software a hotel runs on, covering reservations, check-in and checkout, room assignment, housekeeping, guest folios, rates, and billing. Unlike a generic SaaS (Software as a Service) database, it is the system every other system talks to.

A hotel PMS holds guest personally identifiable information (PII) such as names, email addresses, phone numbers, physical addresses, passport numbers, and stay history. It connects to door locks, point-of-sale (POS) systems, payment processors, and customer relationship management (CRM) platforms. A single compromised credential in the PMS can cascade across the entire property technology stack.

The threat is real and growing. A VikingCloud survey of North American hotels found 82% experienced a successful cyberattack in a single summer, with POS and payment systems targeted in 72% of cases and front desk systems in 34%. The Otelier platform breach exposed 7.8 terabytes of guest data over three months before anyone noticed, originating from a single set of stolen employee credentials, with reporting also citing exposure of 39 million reservation records.

The PMS is the highest-value target in the hotel technology stack because of its integrations. According to the Verizon 2025 Data Breach Investigations Report, third-party involvement in breaches doubled to 30% of all incidents, up from 15% the prior year. For a hotel buyer evaluating a PMS vendor, that statistic describes the risk profile of every integration in the stack.

SOC 2 Type I vs. SOC 2 Type II: Key Differences

SOC 2 is an attestation report rather than a certification. A licensed CPA firm examines a service organization's controls against the AICPA's Trust Services Criteria and issues an opinion. SOC 2 produces no certificate to display on a wall, and no government body issues or enforces it. SOC 2 is a voluntary framework; enterprise buyers and procurement teams make it effectively mandatory by requiring the report before signing contracts. The table below shows how Type I and Type II differ on the points buyers weigh most.

Dimension SOC 2 Type I SOC 2 Type II
What It Tests Whether controls are suitably designed at a single point in time Whether controls operated effectively over a defined observation period
Observation Period None, point-in-time snapshot Typically 6 months for a first audit, 12 months for annual renewals
Total Timeline One to three months Six to fifteen months from start to final report
What Enterprise Buyers Require Accepted only as interim or first-step proof The report most enterprise procurement teams actually require
Validity Considered stale after 12 months in practice Valid for 12 months, renewed annually

SOC 2 Compliant vs. SOC 2 Certified

"SOC 2 certified" is not a real designation. SOC 2 is an auditing process that produces an attestation report rather than a certification. A vendor that says it is "SOC 2 certified" is using imprecise language. The correct request is a direct one: "Please share your SOC 2 Type II report." A vendor that cannot produce the report has no attestation to show and only a claim.

What SOC 2 Compliance Requires From a PMS Vendor

SOC 2 compliance requires a licensed CPA firm to examine a service organization's controls against the AICPA's Trust Services Criteria and issue a formal opinion on those controls. The criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy. The opinion addresses whether controls are suitably designed (Type I) or operated effectively over time (Type II).

Security is the only mandatory criterion; the remaining four are selected based on the vendor's service commitments and customer requirements. For a hotel PMS buyer, the criteria that matter most are Security, Availability, and Confidentiality. Privacy becomes relevant when the vendor processes EU-resident data alongside GDPR (General Data Protection Regulation) obligations.

The Vendor Request List: Questions to Ask a Hotel PMS Vendor

The list below can go directly into a vendor security questionnaire or an email to a PMS vendor's security or compliance contact. Request each item in writing before signing.

Get Help With Your Security Questionnaire

How SOC 2 Relates to PCI DSS, GDPR, ISO 27001/27018, and HIPAA

SOC 2 is one of several frameworks a hotel PMS vendor may claim. These frameworks are frequently conflated, but each addresses a different obligation, and holding one does not satisfy another.

SOC 2 and PCI DSS. SOC 2 and PCI DSS serve fundamentally different purposes: PCI DSS follows an organization's payment role and data architecture, while SOC 2 follows customer-assurance needs around a defined service-organization system. A clean SOC 2 report does not make a vendor PCI DSS compliant. PCI DSS has its own scope, its own validation artifacts, and its own accepting entities. The PCI Security Standards Council does not issue a PCI DSS certificate. Compliance is validated through the acquiring bank relationship.

SOC 2 and GDPR. A company can pass a SOC 2 audit and still be fully out of step with GDPR, because SOC 2 only covers system security and does not address GDPR requirements such as lawful bases for data collection, data subject rights management, breach notification within 72 hours, and privacy documentation. GDPR is a legally binding EU law, while SOC 2 is a voluntary attestation framework. Both require overlapping technical controls, but GDPR adds statutory obligations that no SOC 2 report addresses.

SOC 2 and ISO 27001/27018. ISO 27001 is an internationally recognized certification for an Information Security Management System (ISMS), issued by an accredited certification body and valid for three years with annual surveillance audits. ISO 27018 extends that framework to protecting personal data in cloud environments. The AICPA's own mapping shows 80%+ overlap between SOC 2 and ISO 27001 at the control level. However, the two produce different artifacts, an attestation report versus a certificate, and neither replaces the other.

SOC 2 and HIPAA. HIPAA (Health Insurance Portability and Accountability Act) is a US federal law governing protected health information (PHI). There is no HHS-issued HIPAA certificate, and a SOC 2 report cannot replace HIPAA compliance. For hotel operators, HIPAA is almost never directly relevant because hotels do not handle PHI in the clinical sense. A vendor claiming SOC 2 satisfies HIPAA requirements is conflating two unrelated frameworks.

How long is a SOC 2 report valid? A SOC 2 Type II report covers a defined observation period and is generally considered current for 12 months from the period end date. Buyers should ask when the certification was last renewed and request the most recent report. A report ending 14 months ago describes a vendor whose controls may have changed materially since the auditor last looked.

Who performs a SOC 2 audit? SOC 2 reports must be issued by a licensed CPA (Certified Public Accountant) firm. The auditor reviews the organization's system description, tests controls against the selected Trust Services Criteria, and issues a formal opinion. A readiness assessment beforehand is optional but strongly recommended for first-time audits.

How long does a SOC 2 Type II audit take? A SOC 2 Type II audit runs six to fifteen months in total from start to final report, because controls must operate over the observation period before the formal audit begins. The observation period itself is typically six months for a first audit and twelve months for annual renewals.

How Stayntouch's Security Posture Maps to Each Framework

Stayntouch states its security posture precisely. The points below reflect what Stayntouch actually holds today.

SOC 2 Type I. Stayntouch holds a SOC 2 Type I attestation, confirming that its security controls are suitably designed. The Type II observation period, which tests whether those controls operated effectively over time, is the next step in the program.

PCI DSS Level 1 for Stayntouch Pay. PCI DSS Level 1 is the most stringent tier of the card industry's security standard, applied to the highest transaction volumes. This certification applies specifically to Stayntouch Pay, the integrated payment product, not to the entire platform. Stayntouch Pay uses tokenization, which replaces real card numbers with meaningless substitute values so raw card data is never stored in the PMS. It also uses point-to-point (P2P) encryption, which scrambles card data from the moment it is entered until it reaches the processor.

GDPR. Stayntouch is GDPR-compliant, covering the handling of EU-resident guest data across its platform. That compliance extends across the 60+ countries and 6 regions where Stayntouch operates, including North America, the Caribbean, Central and South America, Europe, Middle East and Africa, and Asia Pacific. Jurisdictional diligence is completed in advance on the customer's behalf rather than left to the hotel operator to research.

ISO 27001/27018. Stayntouch holds ISO 27001 and ISO 27018 certifications, covering its information security management system and the protection of personal data in cloud environments respectively.

Infrastructure. Stayntouch runs on AWS (Amazon Web Services) Private VPC (Virtual Private Cloud), an isolated, private section of cloud infrastructure dedicated to Stayntouch's environment and separate from shared public cloud resources.

Security Program. The ongoing security program combines continuous monitoring with scheduled reviews. Daily perimeter and application vulnerability scanning runs alongside quarterly ASV (Approved Scanning Vendor) and vulnerability scans, while system-wide patching happens quarterly. Penetration testing and security and secure-coding training for all employees occur annually.

Scoped Integration Access. Every integration authenticates using OAuth. OAuth grants an application limited, revocable access without sharing a master password. It functions as a digital valet key that works for one application and can be revoked instantly. Each connected application is restricted to only the data it needs, so a door lock application can see a room number and checkout date but cannot access payment details or home addresses. A breach in one connected application therefore cannot expose the hotel's full database.

Hotel IT directors, controllers, and general managers who receive a vendor security questionnaire with a deadline can expect Stayntouch to answer that questionnaire with evidence rather than adjectives.

Review Stayntouch's Compliance Documentation

What to Do When a Vendor Cannot Produce a SOC 2 Report

A vendor that cannot produce a SOC 2 report, or offers a Type I when a Type II is required, is not automatically disqualified. The gap must be addressed before signing. Typical response options include requiring remediation of specific control gaps before onboarding, negotiating contract terms with security improvement milestones and audit rights, implementing compensating controls, or escalating to a documented risk acceptance decision by the appropriate authority.

Compensating controls worth negotiating into the contract when a SOC 2 Type II report is absent include:

  • A contractual breach notification window stated in hours from vendor discovery. Seventy-two hours is the GDPR standard and a reasonable baseline for any vendor handling guest PII.
  • Annual audit rights, giving the hotel the right to request updated security documentation or accept an independent third-party audit report in lieu of direct access.
  • A subprocessor change notification requirement, so the hotel is informed before the vendor adds a new third party that will process guest data.
  • A data return and certified deletion clause, specifying how guest data is returned or destroyed at contract end and on what timeline.
  • A security improvement milestone clause, with a defined target date for the vendor to achieve SOC 2 Type II attestation and a material adverse change right if the milestone is missed.
  • Evidence of annual penetration testing and quarterly vulnerability scanning, even in the absence of a full SOC 2 report.
  • Confirmation that the PMS application, not just the underlying cloud infrastructure, is covered by whatever security program the vendor operates.

Roughly one-third of growth-stage vendors hold SOC 2 Type I but not Type II, and another third hold neither certification and instead offer a "security overview" document when asked for a SOC 2 report. Knowing which category a vendor falls into before signing is core due diligence.

Frequently Asked Questions About SOC 2 for Hotel PMS Buyers

The questions below address details hotel buyers often raise once they start reviewing SOC 2 reports.

How Often Is SOC 2 Compliance Renewed?

SOC 2 reports are typically renewed annually. A Type II report covers a defined observation period, usually 12 months for annual renewals, and a report older than 12 months is generally considered stale by procurement teams. Most organizations that hold SOC 2 Type II run a continuous compliance program and issue a new report each year covering the prior 12-month period.

What Is a SOC 2 Type II Compliance Checklist?

A SOC 2 Type II compliance checklist is the set of controls an organization must implement, operate, and evidence across the selected Trust Services Criteria over the observation period. The SOC 2 Security criterion (the AICPA Common Criteria, CC1–CC9) requires controls covering the control environment, communication and information, risk assessment, monitoring of controls, control activities, logical and physical access, system operations, change management, and risk mitigation. Each additional criterion adds further controls, such as capacity planning and backup procedures for Availability and data classification and disposal for Confidentiality. The auditor samples evidence of each control operating across the full observation period.

How Much Does SOC 2 Compliance Cost a Vendor?

SOC 2 Type II audit fees from reputable CPA firms typically range from roughly $20,000 to $100,000 depending on scope, the number of Trust Services Criteria selected, and the complexity of the systems in scope. Total first-year program costs, including readiness consulting, compliance tooling, and remediation, are typically higher. Annual renewal costs drop once foundational controls are in place. These figures reflect the vendor's cost of obtaining and maintaining the attestation, not costs passed directly to hotel buyers.

Conclusion

Hotel buyers should treat "SOC 2 compliant" as a starting point and ask for the attestation behind the claim. The evidence that matters is a SOC 2 Type II report that covers the PMS application itself, is issued by a licensed CPA firm, has a period end date within the last 12 months, and includes an exception table worth reading.

As outlined in the Key Takeaways, Stayntouch holds SOC 2 Type I, PCI DSS Level 1 for Stayntouch Pay, GDPR compliance, and ISO 27001/27018 certification, all on AWS Private VPC infrastructure with scoped OAuth integrations. When a security review lands on your desk with a deadline attached, Stayntouch can respond with concrete documentation and tested controls.

Start Your Security Review

Read Next

Turn a more connected stack into a better stay.

See how Stayntouch can support the operating moments that matter most to your hotel team.

Schedule demo