OnwynStandards › SOC 2 (AICPA Trust Services Criteria)

Scheme / framework · 2017 (2022 points of focus)

SOC 2 (AICPA Trust Services Criteria)

SOC 2 is a US-origin attestation scheme in which a CPA firm audits your controls against the AICPA Trust Services Criteria and issues a report your customers can rely on. It is the de-facto entry ticket for selling SaaS to US and international enterprise buyers. Every report covers the Security criteria (the Common Criteria CC1-CC9); Availability, Confidentiality, Processing Integrity, and Privacy are added by choice. A Type I report assesses control design at a point in time; a Type II report tests operating effectiveness over a period, typically 3-12 months — Type II is what sophisticated buyers ask for.

37
Requirements
10
Areas
23
Recommended documents
1
Mapped frameworks
Start SOC 2 free Have us do it instead

What this standard asks for

Every requirement in SOC 2 (AICPA Trust Services Criteria), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Control environment (CC1)

5 requirements

  • CC1.1Commitment to integrity and ethical values
  • CC1.2Board independence and oversight
  • CC1.3Organizational structure, reporting lines and authorities
  • CC1.4Commitment to competence
  • CC1.5Accountability for internal control responsibilities

Communication & information (CC2)

3 requirements

  • CC2.1Quality information to support internal control
  • CC2.2Internal communication of control information
  • CC2.3External communication of control information

Risk assessment (CC3)

4 requirements

  • CC3.1Specifying suitable objectives
  • CC3.2Identifying and analyzing risk
  • CC3.3Considering fraud risk
  • CC3.4Identifying and assessing significant change

Monitoring activities (CC4)

2 requirements

  • CC4.1Ongoing and separate evaluations of controls
  • CC4.2Evaluating and communicating control deficiencies

Control activities (CC5)

3 requirements

  • CC5.1Selecting and developing control activities
  • CC5.2Selecting and developing technology general controls
  • CC5.3Deploying controls through policies and procedures

Logical & physical access (CC6)

8 requirements

  • CC6.1Logical access security software, infrastructure, and architectures
  • CC6.2User registration, authorization and deprovisioning
  • CC6.3Role-based access, least privilege and access review
  • CC6.4Physical access to facilities and assets
  • CC6.5Disposal of assets and data
  • CC6.6Protection against external access threats
  • CC6.7Protection of information in transmission and on endpoints
  • CC6.8Prevention and detection of unauthorized or malicious software

System operations (CC7)

5 requirements

  • CC7.1Detection of configuration changes and new vulnerabilities
  • CC7.2Monitoring for anomalies and security events
  • CC7.3Evaluation of security events
  • CC7.4Incident response program
  • CC7.5Recovery from incidents

Change management (CC8)

1 requirement

  • CC8.1Change management over infrastructure, data and software

Risk mitigation (CC9)

2 requirements

  • CC9.1Risk mitigation for business disruption
  • CC9.2Vendor and business partner risk management

Optional trust services categories

4 requirements

  • A1Availability (optional category)
  • C1Confidentiality (optional category)
  • PI1Processing integrity (optional category)
  • P1Privacy (optional category)

The documents you will end up with

The recommended document set for SOC 2 (AICPA Trust Services Criteria) — 23 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

System Description

Your own account of the service, its boundaries, the infrastructure behind it and the controls you run — Section III of the report, written by you rather than the auditor.

Information Security Policy Set

The written policies staff are held to, which is how service organisations usually evidence that controls are deployed through policy rather than habit.

Code of Conduct and Ethics

The behavioural standard everyone signs up to, and what happens when someone departs from it.

Org Chart and Oversight Charter

Shows the reporting lines and who provides independent oversight of management — usually a board or advisory charter plus an org chart.

HR and Competence Procedures

How you hire, define what a role needs, and hold people accountable for the control work in their job — including performance and disciplinary routes.

Risk Assessment Procedure and Register

The documented risk process most service organisations use to show they identify risk, consider fraud, and reassess when things change.

Control Matrix

Maps each Trust Services criterion to the specific control you run and the evidence that proves it — the working document that drives the whole audit.

Control Monitoring and Deficiency Procedure

How you check your own controls between audits and what happens to a deficiency once someone finds one.

Internal Control Communication Materials

How people are told what their control responsibilities are — onboarding decks, policy acknowledgements, security channel announcements.

Access Control Policy

How identities are created, what access each role gets, and how access is removed and periodically reviewed.

Physical Security Policy

How offices and any physical assets are protected, and what you inherit from your cloud provider instead.

Asset and Data Disposal Procedure

How devices and storage are wiped or destroyed when they leave, and how that is recorded.

Network and Endpoint Security Policy

The technical defences at the boundary and on laptops: firewalls, encryption in transit, endpoint protection and anti-malware.

Vulnerability Management Policy

How you detect new vulnerabilities and configuration drift, how you rank them, and the deadlines for fixing each severity.

Logging and Monitoring Policy

What is logged, what raises an alert, and how someone decides whether an alert is actually a security event.

Incident Response Plan

Who does what during a security incident, how customers and authorities are told, and how service is restored.

Change Management Policy

How code and infrastructure changes are reviewed, approved, tested and released, including emergency changes.

Business Continuity and Disaster Recovery Plan

How the service survives and recovers from disruption, with the recovery targets you have committed to customers.

Vendor Management Policy

How subservice organisations and vendors are assessed before use and monitored afterwards, including reviewing their own reports.

Availability and Capacity Plan

Capacity headroom, redundancy and the recovery objectives behind any uptime commitment you have made.

Data Classification and Confidentiality Policy

What counts as confidential customer information, how it is handled, and when it is destroyed.

Processing Integrity Procedures

How you show that processing is complete, accurate and authorised — input validation, reconciliations and error handling.

Privacy Notice and Privacy Procedures

What you tell individuals about their personal information and how you honour their choices about it.

Work that counts twice

SOC 2 (AICPA Trust Services Criteria) overlaps with 1 other framework in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start SOC 2 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.