backBack

SOC2 Type II: Building trust into Nokia Network as Code

SOC 2 Type II assurance reinforces trust in Nokia Network as Code across security, availability and confidentiality.

August 28, 2026

Trust is one of those words everyone uses, but in digital services it has to mean something very practical. Can the platform protect customer data? Can it run reliably over time? Can controls work consistently, not just on the day of an assessment but every day after it?

That is why achieving SOC 2 Type II assurance for Nokia Network as Code and API Hub is an important milestone for our team. The independent examination covered the Network as Code platform using Nokia’s API Hub Technology, focusing on controls relevant to security, availability, and confidentiality.

Why this matters for developers and enterprisesheader link

Network as Code brings together programmable network capabilities, API discovery, publishing, management and monetization through developer-friendly services. In practical terms, it helps developers, communications service providers and enterprises connect applications with network capabilities through governed APIs instead of complex one-off integrations.

That convenience must be matched by assurance. As more teams use APIs to build network-aware experiences, they need confidence that the platform is operated with disciplined processes for access, change, monitoring, resilience and data protection. SOC 2 Type II helps answer that need in a structured and evidence-based way.

For example, a developer building an application that verifies a user’s device location or connectivity status should not have to understand every network integration behind the scenes. They should be able to call a governed API, know who can access it, see how changes are controlled, rely on monitoring when something goes wrong and trust that sensitive data is handled with clear protection measures.

What we provedheader link

SOC 2 Type II is not a point-in-time badge. It assesses whether controls are designed appropriately and operate effectively over time. At a high level, the examination tested controls across security governance, employee awareness, risk assessment, access management, encryption, network protection, vulnerability management, monitoring, incident response, change management, backup and recovery, vendor oversight, data retention and confidentiality practices.

The review also reflected the cloud operating model behind the platform, where Nokia operates the application and service environment while relying on a major cloud provider for underlying hosting responsibilities. That shared-responsibility model makes clear control of ownership especially important, and it is one reason why repeatable governance, monitoring and vendor assurance matter so much.

Behind the certificate is a lot of real work: teams aligning evidence, validating processes, closing gaps, testing controls and making sure security and privacy are not treated as separate checkpoints but as part of how we build and run the platform. This accomplishment belongs to everyone who contributed across engineering, product, operations, security, privacy and compliance.

Trust as part of the developer experienceheader link

A good developer experience is not only about fast onboarding or well-documented APIs. It is also about confidence. When teams experiment, test and move toward production, they need a platform they can trust with their applications, users and business outcomes.

With SOC 2 Type II assurance, we can give customers and partners stronger confidence that Network as Code and API Hub are supported by enterprise-ready practices. These include high-level controls for identity and access, secure change delivery, operational monitoring, incident handling, resilience, data protection, and confidentiality. Just as importantly, the assessment found that the tested controls operated effectively throughout the review period.

What comes nextheader link

This milestone is not the end of the journey. It raises the bar for how we keep improving. As Network as Code continues to grow, our focus remains on strengthening controls, simplifying assurance for customers and partners, and keeping trust built into the way developers discover, test and use network APIs.

If you are building network-aware applications, now is a great time to explore what Network as Code can do for you. Visit the Network as Code Developer Portal, try the APIs and build with the confidence that trust is part of the platform.

How to request copy of SOC2 reportheader link

Customers and partners who need a copy of the SOC 2 Type II report can request access through their Nokia sales or support contact, or by using the Nokia Network as Code support channel. A valid non-disclosure agreement must be in place between Nokia and your organization before a copy of the SOC 2 report can be shared. Please include your organization name, business justification and intended use of the report in the request. For Network as Code support, you can also contact [email protected].