- Select the trust services categories in scope and record why the others are out
- Operate each control on its cadence and collect the evidence as it happens
- Keep the access review, change and incident records continuous for the Type II period
- Track vendor reviews and the subservice organisations they cover
- Assemble the auditor request list from records that already exist
SOC 2 (TSC 2017, rev. 2022)
Not a certification but an attestation. An independent auditor reports on whether your controls were designed properly, and for Type II, whether they operated over a period.
- CC1.0Control environment5
- CC2.0Communication and information3
- CC3.0Risk assessment4
- CC4.0Monitoring activities2
- CC5.0Control activities3
- CC6.0Logical and physical access controls8
- CC7.0System operations5
- CC8.0Change management1
- CC9.0Risk mitigation2
- A1.0Availability3
- C1.0Confidentiality2
- PI1.0Processing integrity5
- P1.0 to P8.0Privacy18
SOC 2, in practice.
Trust services criteria for security, availability, processing integrity, confidentiality and privacy.
Technology and service providers whose enterprise customers make the report a condition of the contract, usually during procurement or vendor review.
The clause numbers and titles above are the standard's own public structure. The standard itself is copyright of its issuing body and you buy it from them. What we add is the interpretation underneath, and that lives in your workspace.
Every month, on a schedule you can check.
This is the running work for this standard specifically. The general shape is the same across all of them.
- Access reviews with reviewer, date and the accounts examined
- Change records linked to approval and deployment
- Incident records with detection, response and closure
- Vendor reviews and subservice organisation monitoring
- Policy set with acknowledgement records per employee
Each one is filed against the requirement it satisfies as the work happens, so the pack for the next visit already exists.
Standards that share the structure.
ISO 9001:2015
The quality management standard most certified organisations start with, and the one most other management system standards borrow their structure from.
ISO 22301:2019
The continuity standard, built around one question: when the thing you deliver stops, how quickly does it come back, and who decided that was fast enough.
ISO/IEC 27001:2022
The information security management standard. The management system clauses set the discipline, and Annex A supplies the control set you select from and justify.
Name a clause in SOC 2 and we will open it.
The requirement, the control attached to it, the evidence that satisfies it, and the audit checklist it generates. Nothing prepared in advance, because there is nothing to prepare.
