A SOC 2 audit is a third-party evaluation of a service organization's controls relevant to security, availability, processing integrity, confidentiality, and/or privacy. It's designed to provide assurance to customers and other stakeholders that a service organization has implemented and is effectively maintaining appropriate controls.
vSphere
Current and historical Hardening guides are available at https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-configuration-hardening-guide/vsphere