What security certifications (SOC 2, ISO 27001) should an online proctoring vendor have?

TL;DR: At minimum, ask for a SOC 2 Type II report, which independently verifies the vendor's data-handling controls over time, not just at a point in time. Depending on your region and audience, also confirm GDPR and/or FERPA compliance documentation. ISO 27001 certification is a strong plus for global enterprise or certification-body deals. Always get a signed data processing agreement (DPA) and a written data retention policy.

Why this matters for proctoring specifically

Proctoring vendors handle some of the most sensitive data an institution collects: webcam video, government ID scans, biometric face data, and screen recordings. A breach or careless retention policy here is a much bigger liability than a typical SaaS data leak.

What each standard actually covers

Standard/documentWhat it verifiesWhy it matters for proctoring
SOC 2 Type IISecurity controls operated effectively over a period (usually 6-12 months)Confirms ongoing practice, not a one-time snapshot
ISO 27001Formal information security management systemUseful for global, cross-border certification bodies
GDPR compliance docsEU data subject rights and processing basisRequired if testing EU candidates
FERPA alignmentUS student education record protectionsRequired for US higher-ed exam data
Signed DPAContractual data processing termsLegal accountability if something goes wrong

How to vet a vendor

  1. Request the SOC 2 Type II report directly (not just a badge on the website).
  2. Ask for the vendor's data retention schedule in writing — how long is webcam/ID data kept, and when is it deleted?
  3. Confirm where data is stored/processed (which region's servers) if you have cross-border students.
  4. Get a signed DPA before rolling out to real candidates.
  5. Ask what happens to data if you terminate the contract — export and deletion terms should be explicit.

FAQ

Is SOC 2 required by law? No, it's a voluntary industry standard, but its absence is a red flag for a vendor handling biometric and ID data.

Does GDPR compliance matter if I'm US-only? Not directly, but FERPA and state privacy laws impose similar obligations — ask for the US-equivalent documentation instead.

What's the biggest overlooked risk? Data retention — many institutions don't ask how long webcam recordings and ID scans are kept, or whether they're deleted on schedule.

By Pinal Dave Last updated: 2026-07-26