AICPA · International61 requirements

SOC 2 (TSC 2017, rev. 2022)

Not a certification but an attestation. An independent auditor reports on whether your controls were designed properly, and for Type II, whether they operated over a period.

Clause structure in CompStack
  • CC1.0Control environment5
  • CC2.0Communication and information3
  • CC3.0Risk assessment4
  • CC4.0Monitoring activities2
  • CC5.0Control activities3
  • CC6.0Logical and physical access controls8
  • CC7.0System operations5
  • CC8.0Change management1
  • CC9.0Risk mitigation2
  • A1.0Availability3
  • C1.0Confidentiality2
  • PI1.0Processing integrity5
  • P1.0 to P8.0Privacy18
25 clauses total61 requirements
Who carries this

SOC 2, in practice.

Trust services criteria for security, availability, processing integrity, confidentiality and privacy.

Technology and service providers whose enterprise customers make the report a condition of the contract, usually during procurement or vendor review.

A note on the text

The clause numbers and titles above are the standard's own public structure. The standard itself is copyright of its issuing body and you buy it from them. What we add is the interpretation underneath, and that lives in your workspace.

What the service does with it

Every month, on a schedule you can check.

This is the running work for this standard specifically. The general shape is the same across all of them.

We carry
  • Select the trust services categories in scope and record why the others are out
  • Operate each control on its cadence and collect the evidence as it happens
  • Keep the access review, change and incident records continuous for the Type II period
  • Track vendor reviews and the subservice organisations they cover
  • Assemble the auditor request list from records that already exist
Evidence the assessor asks for
  • Access reviews with reviewer, date and the accounts examined
  • Change records linked to approval and deployment
  • Incident records with detection, response and closure
  • Vendor reviews and subservice organisation monitoring
  • Policy set with acknowledgement records per employee

Each one is filed against the requirement it satisfies as the work happens, so the pack for the next visit already exists.

Walk it yourself

Name a clause in SOC 2 and we will open it.

The requirement, the control attached to it, the evidence that satisfies it, and the audit checklist it generates. Nothing prepared in advance, because there is nothing to prepare.