What SOC 2 assesses
A SOC 2 examination is performed by an independent CPA firm against the AICPA Trust Services Criteria. The Security criteria, known as the common criteria, are always in scope. Availability, Confidentiality, Processing Integrity and Privacy are added only when relevant to the service.
Type I and Type II
- Type I reports on whether controls are suitably designed at a point in time.
- Type II reports on whether controls operated effectively across an observation period, commonly three to twelve months.
- Most customers asking for SOC 2 want a Type II report.
What you need in place
- A system description that accurately defines the service in scope.
- Policies that describe what your organisation actually does.
- Controls with named owners and a defined operating frequency.
- Evidence gathered throughout the observation period, not assembled at the end.
- Risk assessment, vendor review, access review and incident records.
Evidence is the common failure point
Design work is usually completed early. What causes problems is the operating evidence: quarterly access reviews that were never recorded, change approvals that live only in chat, onboarding checklists completed informally. Evidence should be produced as a by-product of the work.
How Compliancy is used here
In Compliancy each Trust Services Criterion is mapped to controls. Each control carries an owner, related policies, risks and dated evidence. Readiness shows which controls are operating and what is outstanding before the observation period closes.
Compliancy does not issue SOC 2 reports. Only an independent CPA firm can.
See this in the product
Compliancy holds the controls, evidence and records described above in one platform.