WordPress VIP Completes SOC 2® Type 2 Examination

Independent assessment evaluates controls relevant to the security and availability of the WordPress VIP Enterprise CMS.

Published on

by

Read time:

1–2 minutes
Woman smiling at laptop with a SOC 2 Type 2 badge on a blue and black graphic background.

WordPress VIP today announced that it has successfully completed its first System and Organization Controls (SOC) 2® Type 2 examination, providing customers with an independent assessment of controls relevant to the the Trust Services Criteria of Security and Availability of the WordPress VIP Enterprise CMS.

For enterprise organizations, independent assessments such as SOC 2 reports provide important information during security reviews, procurement processes, and ongoing vendor oversight. They can also help customers evaluate a platform’s controls more efficiently, reducing the need to conduct separate, detailed reviews for every service provider. WordPress VIP’s SOC 2 Type 2 examination builds on its prior SOC 2 Type 1 examination and FedRAMP authorization, providing a fuller picture of the platform’s overall security program.

Fortreum conducted the examination and evaluated the operation of relevant controls over an observation period from March 1 through July 17, 2026. The assessment covered areas including access control, secure development, configuration management, governance, capacity monitoring, backup and recovery, and recovery testing.

Unlike a Type 1 examination, which evaluates whether controls are suitably designed and implemented at a specific point in time, a Type 2 examination evaluates whether those controls operated effectively over a defined period.

“Enterprise customers need confidence that the platforms behind their digital experiences are built on rigorous security and availability practices. Our SOC 2 Type 2 examination is proof of that rigor. Reliability and security aren’t incidental here — they’re engineered in. That means uptime our customers can count on, an experience their own customers never have to think twice about, and vendor due diligence that just got a lot easier.”

– Avik Mohan, Chief Governance, Risk and Compliance Officer, WordPress VIP

The WordPress VIP SOC 2 report is available to customers through the WordPress VIP Trust Center, subject to a nondisclosure agreement. The report applies to the WordPress VIP Enterprise CMS and does not include Parse.ly.

For more information about WordPress VIP’s security and compliance programs, visit the WordPress VIP Trust Center.

Author

Don’t miss The Brief.

Timely topics, practical insights, decisive steps. Every two weeks.

Loading form …

Categories

Don’t miss The Brief.

Timely topics, practical insights, decisive steps. Every two weeks.