What it means

SOC 2 is a voluntary audit standard governed by the AICPA. It tells buyers how a vendor controls data security, availability, and confidentiality. Per Gartner, a Type II audit period typically spans 6 to 12 months, and costs for a mid-market SaaS vendor range from $30,000 to $100,000 depending on scope and auditor. FERPA — codified at 20 U.S.C. § 1232g — is a federal statute enforced by the U.S. Department of Education. It applies to any institution receiving federal education funds and protects records directly related to a student. Violations can cost an institution its federal funding. Vendors enter FERPA's scope through the school official exception at 34 CFR 99.31(a)(1). Under that rule, a vendor may access education records only when it performs a function the institution would otherwise handle itself, operates under the institution's direct control, and uses records solely for authorized purposes. That requirement makes FERPA obligations the vendor's problem, not just the school's.

What to do

SOC 2 FERPA education software compliance is essential for any vendor handling student records. FERPA (20 U.S.C. § 1232g) protects more than 68 million U.S. students; vendors enter its scope through the school official exception at 34 CFR 99.31(a)(1), which requires direct institutional control and authorized-use-only restrictions. SOC 2 Type II is an independent AICPA audit confirming that security controls operated effectively over a defined period — typically 6 to 12 months — and Gartner estimates the cost for a mid-market SaaS vendor at $30,000 to $100,000. Universities increasingly require SOC 2 Type II attestation as a procurement prerequisite. Achieving both obligations requires mapping every student data flow against 34 CFR Part 99, confirming school official status, completing a Type II audit period, and contractually committing to authorized-use-only data handling.

SOC 2 FERPA education software compliance: what each standard requires

SOC 2 is a voluntary AICPA audit; FERPA is a federal statute under 20 U.S.C. § 1232g. A SOC 2 Type II audit period typically spans 6 to 12 months, per Gartner. FERPA obligations attach the moment a vendor accesses student records under 34 CFR 99.31(a)(1), making both standards binding for education software vendors.

SOC 2 is a voluntary audit standard governed by the AICPA. It tells buyers how a vendor controls data security, availability, and confidentiality. Per Gartner, a Type II audit period typically spans 6 to 12 months, and costs for a mid-market SaaS vendor range from $30,000 to $100,000 depending on scope and auditor.

FERPA — codified at 20 U.S.C. § 1232g — is a federal statute enforced by the U.S. Department of Education. It applies to any institution receiving federal education funds and protects records directly related to a student. Violations can cost an institution its federal funding.

Vendors enter FERPA's scope through the school official exception at 34 CFR 99.31(a)(1). Under that rule, a vendor may access education records only when it performs a function the institution would otherwise handle itself, operates under the institution's direct control, and uses records solely for authorized purposes. That requirement makes FERPA obligations the vendor's problem, not just the school's.

How many students are covered — and why scale matters

More than 68 million U.S. students have education records protected by FERPA, per the NCES Digest of Education Statistics 2023. That figure spans 5,916 Title IV-funded postsecondary institutions identified in IPEDS data for 2022–23. Any vendor touching even one record at a covered school carries the same legal exposure as one serving millions.

The NCES Digest of Education Statistics 2023 reports approximately 49.6 million students enrolled in public elementary and secondary schools in fall 2022 and approximately 18.6 million at postsecondary degree-granting institutions the same year. Combined, more than 68 million U.S. students have education records protected by FERPA at any given academic year.

IPEDS data for 2022–23 identify 5,916 degree-granting postsecondary institutions that received Title IV federal funding and are therefore subject to FERPA. Every vendor that accesses data at any one of them operates inside FERPA's reach.

What a SOC 2 Type II report proves to a school buyer

A SOC 2 Type II report covers 6 to 12 months of operating effectiveness, per Gartner. That is materially different from a Type I snapshot. Inside Higher Ed (2023) found data security ranked as the top vendor evaluation criterion at universities — ahead of functionality and price.

A SOC 2 Type I report shows controls were designed correctly at a single point in time. A Type II report shows those controls actually worked over an audit period that, per Gartner, typically spans 6 to 12 months — a meaningful distinction because a snapshot says little about day-to-day discipline.

Procurement teams at universities are paying close attention. Inside Higher Ed (2023) reported that research universities increasingly require SOC 2 Type II attestation as a contractual prerequisite, with some mandating re-attestation every 12 months. Data security and privacy compliance ranked as the top vendor evaluation criterion cited by campus IT and legal officers, ahead of functionality and price.

FERPA's school official exception: the legal hook that binds vendors

Under 34 CFR 99.31(a)(1), a vendor gains lawful access to student records only by meeting 3 conditions set by the U.S. Department of Education. Misuse keeps primary liability with the institution, so buyers vet vendors rigorously. State laws like California's SOPIPA and New York's Education Law 2-d add direct vendor obligations on top.

FERPA does not give vendors a blanket right to touch student records. Under 34 CFR 99.31(a)(1), a vendor may access education records as a "school official" only when it performs a service the institution would otherwise handle with its own staff, operates under the institution's direct control, and uses records solely for authorized purposes.

When a vendor violates any one of those conditions, the institution bears primary FERPA liability — giving schools a strong financial reason to vet vendors carefully.

State legislatures have added a second layer of exposure that falls directly on vendors. As of 2023, at least 145 student data privacy laws had been enacted across U.S. states, per Education Week. California's SOPIPA and New York's Education Law 2-d are among the most vendor-restrictive, imposing data security and breach-notification obligations on edtech vendors regardless of whether an institution sits in between.

At least 3 major edtech vendors faced contract terminations in 2022–2023 after institutional audits uncovered FERPA data-handling deficiencies, per Higher Ed Dive (2024).

A vendor roadmap to SOC 2 and FERPA compliance

Step 1 is a full data inventory mapped against 34 CFR Part 99. SOC 2 Type II audit periods typically span 6 to 12 months, per Gartner, so sequencing matters. FERPA obligations attach the moment a vendor touches student records, making parallel legal and technical work essential from day one.

Step 1: Build a full data inventory. Map every student record your product touches, classify it under FERPA's definition at 34 CFR Part 99, and confirm whether you qualify as a school official under 34 CFR 99.31(a)(1). Without this map, every step that follows is guesswork.

Step 2: Run a gap assessment against the AICPA Trust Services Criteria and document which controls — encryption, access logging, incident response — are missing or incomplete. For products that use AI to process student data, OWASP recommends placing access controls and audit logging at the model inference layer, not only at the application layer.

Step 3: Engage a licensed CPA firm for a SOC 2 readiness review, then begin the Type II audit period. Audit periods typically span 6 to 12 months, per Gartner, and costs for a mid-market SaaS vendor range from $30,000 to $100,000 depending on scope and auditor. Plan that timeline before a procurement deadline forces your hand.

Step 4: In parallel, draft Data Processing Agreements mirroring FERPA's school official language — direct institutional control, authorized purposes only — and train engineering and customer-success staff before any contract is signed.

SOC 2 Type II vs. FERPA: key compliance dimensions for education software vendors. Sources: U.S. Department of Education (34 CFR Part 99); NCES Digest of Education Statistics 2023; NCES/IPEDS; Gartner; Inside Higher Ed; Education Week; Higher Ed Dive; OWASP LLM Top 10 (2025 edition). Gartner projections are sourced from Gartner research. Year shown only where the FACTS source states a release date.
DimensionFERPASOC 2 Type II
Governing authorityU.S. Department of Education — 20 U.S.C. § 1232g; 34 CFR Part 99AICPA Trust Services Criteria — administered by independent licensed CPA firms
Who must complyAll educational agencies and institutions receiving federal education funds — and vendors accessing education records as 'school officials' under 34 CFR 99.31(a)(1)Voluntary; Gartner projects that by 2025, 60% of organizations will use cybersecurity risk assessments as a primary vendor-selection criterion, and SOC 2 Type II has become the de facto baseline security assurance document in enterprise SaaS procurement
Scope of protected dataRecords directly related to a student and maintained by an institution or a party acting for the institution. AI-generated student records and AI-assisted advising outputs maintained by an institution also qualify (Higher Ed Dive, 2024)Any sensitive customer or operational data in scope of the service organization's systems — defined at audit engagement
Typical cost rangeNo fixed benchmark$30,000 to $100,000 for a mid-market SaaS vendor, depending on scope and auditor (Gartner)
Typical timelineNo fixed audit cycleAudit periods typically span 6 to 12 months (Gartner)
Best fitRequired for all vendors accessing student records at any Title IV-funded institutionAny edtech vendor seeking contractual approval to access institutional data systems
Key riskContract termination and loss of institutional federal funding; at least 3 major edtech vendors faced terminations in 2022–2023 (Higher Ed Dive, 2024)Inability to pass procurement review; research universities increasingly require SOC 2 Type II as a contractual prerequisite (Inside Higher Ed, 2023)
Institutions / vendors affected5,916 degree-granting postsecondary institutions receiving Title IV funding; more than 68 million U.S. students covered (NCES/IPEDS; NCES Digest of Education Statistics 2023)Depends on scope of audit engagement
Re-attestation frequencyNo fixed cycleSome institutions mandate re-attestation every 12 months (Inside Higher Ed, 2023)
State-law overlayAt least 145 student data privacy laws enacted across U.S. states as of 2023, including California's SOPIPA and New York's Education Law 2-d (Education Week)
AI-specific considerationsAI-generated records maintained by an institution qualify as education records under FERPA (Higher Ed Dive, 2024)OWASP recommends access controls and audit logging at the model inference layer for AI systems processing education records (OWASP LLM Top 10, 2025 edition)
SourcesU.S. Department of Education (34 CFR Part 99); NCES/IPEDS; Higher Ed DiveGartner; Inside Higher Ed; OWASP LLM Top 10 (2025 edition)