SOC 2

SOC 2 compliance software

Compliancy helps organisations prepare for a SOC 2 examination by mapping Trust Services Criteria to controls, linking policies, owners and evidence, and tracking readiness over the observation period.

What SOC 2 is

  • SOC 2 is an examination performed by an independent CPA firm against the AICPA Trust Services Criteria.
  • A Type I report covers control design at a point in time. A Type II report covers operating effectiveness across an observation period, commonly three to twelve months.
  • The Security criteria (the common criteria) are always in scope. Availability, Confidentiality, Processing Integrity and Privacy are optional.

What organisations need to manage

  • A defined system description and scope
  • Documented policies that match real practice
  • Controls with named owners
  • Evidence collected across the whole observation period
  • Risk assessment and vendor review activity
  • Access reviews, change management and incident records

How Compliancy helps

Criteria mapping

Map each Trust Services Criterion to the controls that address it, and see where nothing is mapped yet.

Evidence over time

Attach evidence to controls with dates so an observation period can be reviewed in one view.

Readiness view

See which controls are operating, which are outstanding, and who owns the remaining work.

Auditor handover

Export control, policy and evidence information in a structured way when the examination begins.

Reporting

Readiness you can show, not assemble.

How it connects to other frameworks

Many SOC 2 controls also satisfy ISO 27001 Annex A requirements. In Compliancy a single control can be mapped to several frameworks, so access control or change management evidence is reused rather than duplicated.

SOC 2 questions

Does Compliancy issue a SOC 2 report?

No. A SOC 2 report can only be issued by an independent CPA firm. Compliancy manages the controls, policies and evidence used during the examination.

Does Compliancy guarantee SOC 2 compliance?

No. Compliancy supports the work; the outcome depends on your controls and your auditor's opinion.

Can Compliancy handle a Type II observation period?

Yes. Evidence is stored with dates so activity across an observation period can be reviewed.

Run SOC 2 in one place.

Compliancy does not issue reports, certificates or legal advice. It manages the program behind them.