SOC 2
SOC 2 compliance software
Compliancy helps organisations prepare for a SOC 2 examination by mapping Trust Services Criteria to controls, linking policies, owners and evidence, and tracking readiness over the observation period.
What SOC 2 is
- SOC 2 is an examination performed by an independent CPA firm against the AICPA Trust Services Criteria.
- A Type I report covers control design at a point in time. A Type II report covers operating effectiveness across an observation period, commonly three to twelve months.
- The Security criteria (the common criteria) are always in scope. Availability, Confidentiality, Processing Integrity and Privacy are optional.
What organisations need to manage
- A defined system description and scope
- Documented policies that match real practice
- Controls with named owners
- Evidence collected across the whole observation period
- Risk assessment and vendor review activity
- Access reviews, change management and incident records
How Compliancy helps
Criteria mapping
Map each Trust Services Criterion to the controls that address it, and see where nothing is mapped yet.
Evidence over time
Attach evidence to controls with dates so an observation period can be reviewed in one view.
Readiness view
See which controls are operating, which are outstanding, and who owns the remaining work.
Auditor handover
Export control, policy and evidence information in a structured way when the examination begins.
SOC 2 readiness
Reporting
Readiness you can show, not assemble.
Compliance overview
Track your compliance performance over time.
Compliance trend
Compliance by category
- Compliant 78%
- In progress 15%
- Non-compliant 7%
How it connects to other frameworks
Many SOC 2 controls also satisfy ISO 27001 Annex A requirements. In Compliancy a single control can be mapped to several frameworks, so access control or change management evidence is reused rather than duplicated.
SOC 2 questions
Does Compliancy issue a SOC 2 report?
No. A SOC 2 report can only be issued by an independent CPA firm. Compliancy manages the controls, policies and evidence used during the examination.
Does Compliancy guarantee SOC 2 compliance?
No. Compliancy supports the work; the outcome depends on your controls and your auditor's opinion.
Can Compliancy handle a Type II observation period?
Yes. Evidence is stored with dates so activity across an observation period can be reviewed.
Related resources
Run SOC 2 in one place.
Compliancy does not issue reports, certificates or legal advice. It manages the program behind them.