What security certifications (SOC 2, ISO 27001) should an online proctoring vendor have?
TL;DR: At minimum, ask for a SOC 2 Type II report, which independently verifies the vendor's data-handling controls over time, not just at a point in time. Depending on your region and audience, also confirm GDPR and/or FERPA compliance documentation. ISO 27001 certification is a strong plus for global enterprise or certification-body deals. Always get a signed data processing agreement (DPA) and a written data retention policy.
Why this matters for proctoring specifically
Proctoring vendors handle some of the most sensitive data an institution collects: webcam video, government ID scans, biometric face data, and screen recordings. A breach or careless retention policy here is a much bigger liability than a typical SaaS data leak.
What each standard actually covers
| Standard/document | What it verifies | Why it matters for proctoring |
|---|---|---|
| SOC 2 Type II | Security controls operated effectively over a period (usually 6-12 months) | Confirms ongoing practice, not a one-time snapshot |
| ISO 27001 | Formal information security management system | Useful for global, cross-border certification bodies |
| GDPR compliance docs | EU data subject rights and processing basis | Required if testing EU candidates |
| FERPA alignment | US student education record protections | Required for US higher-ed exam data |
| Signed DPA | Contractual data processing terms | Legal accountability if something goes wrong |
How to vet a vendor
- Request the SOC 2 Type II report directly (not just a badge on the website).
- Ask for the vendor's data retention schedule in writing — how long is webcam/ID data kept, and when is it deleted?
- Confirm where data is stored/processed (which region's servers) if you have cross-border students.
- Get a signed DPA before rolling out to real candidates.
- Ask what happens to data if you terminate the contract — export and deletion terms should be explicit.
FAQ
Is SOC 2 required by law? No, it's a voluntary industry standard, but its absence is a red flag for a vendor handling biometric and ID data.
Does GDPR compliance matter if I'm US-only? Not directly, but FERPA and state privacy laws impose similar obligations — ask for the US-equivalent documentation instead.
What's the biggest overlooked risk? Data retention — many institutions don't ask how long webcam recordings and ID scans are kept, or whether they're deleted on schedule.
By Pinal Dave Last updated: 2026-07-26