Onwyn › Standards › SOC 2 (AICPA Trust Services Criteria)
Scheme / framework · 2017 (2022 points of focus)SOC 2 (AICPA Trust Services Criteria)
SOC 2 is a US-origin attestation scheme in which a CPA firm audits your controls against the AICPA Trust Services Criteria and issues a report your customers can rely on. It is the de-facto entry ticket for selling SaaS to US and international enterprise buyers. Every report covers the Security criteria (the Common Criteria CC1-CC9); Availability, Confidentiality, Processing Integrity, and Privacy are added by choice. A Type I report assesses control design at a point in time; a Type II report tests operating effectiveness over a period, typically 3-12 months — Type II is what sophisticated buyers ask for.
What this standard asks for
Every requirement in SOC 2 (AICPA Trust Services Criteria), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
Control environment (CC1)
5 requirements
- CC1.1Commitment to integrity and ethical values
- CC1.2Board independence and oversight
- CC1.3Organizational structure, reporting lines and authorities
- CC1.4Commitment to competence
- CC1.5Accountability for internal control responsibilities
Communication & information (CC2)
3 requirements
- CC2.1Quality information to support internal control
- CC2.2Internal communication of control information
- CC2.3External communication of control information
Risk assessment (CC3)
4 requirements
- CC3.1Specifying suitable objectives
- CC3.2Identifying and analyzing risk
- CC3.3Considering fraud risk
- CC3.4Identifying and assessing significant change
Monitoring activities (CC4)
2 requirements
- CC4.1Ongoing and separate evaluations of controls
- CC4.2Evaluating and communicating control deficiencies
Control activities (CC5)
3 requirements
- CC5.1Selecting and developing control activities
- CC5.2Selecting and developing technology general controls
- CC5.3Deploying controls through policies and procedures
Logical & physical access (CC6)
8 requirements
- CC6.1Logical access security software, infrastructure, and architectures
- CC6.2User registration, authorization and deprovisioning
- CC6.3Role-based access, least privilege and access review
- CC6.4Physical access to facilities and assets
- CC6.5Disposal of assets and data
- CC6.6Protection against external access threats
- CC6.7Protection of information in transmission and on endpoints
- CC6.8Prevention and detection of unauthorized or malicious software
System operations (CC7)
5 requirements
- CC7.1Detection of configuration changes and new vulnerabilities
- CC7.2Monitoring for anomalies and security events
- CC7.3Evaluation of security events
- CC7.4Incident response program
- CC7.5Recovery from incidents
Change management (CC8)
1 requirement
- CC8.1Change management over infrastructure, data and software
Risk mitigation (CC9)
2 requirements
- CC9.1Risk mitigation for business disruption
- CC9.2Vendor and business partner risk management
Optional trust services categories
4 requirements
- A1Availability (optional category)
- C1Confidentiality (optional category)
- PI1Processing integrity (optional category)
- P1Privacy (optional category)
The documents you will end up with
The recommended document set for SOC 2 (AICPA Trust Services Criteria) — 23 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
Your own account of the service, its boundaries, the infrastructure behind it and the controls you run — Section III of the report, written by you rather than the auditor.
The written policies staff are held to, which is how service organisations usually evidence that controls are deployed through policy rather than habit.
The behavioural standard everyone signs up to, and what happens when someone departs from it.
Shows the reporting lines and who provides independent oversight of management — usually a board or advisory charter plus an org chart.
How you hire, define what a role needs, and hold people accountable for the control work in their job — including performance and disciplinary routes.
The documented risk process most service organisations use to show they identify risk, consider fraud, and reassess when things change.
Maps each Trust Services criterion to the specific control you run and the evidence that proves it — the working document that drives the whole audit.
How you check your own controls between audits and what happens to a deficiency once someone finds one.
How people are told what their control responsibilities are — onboarding decks, policy acknowledgements, security channel announcements.
How identities are created, what access each role gets, and how access is removed and periodically reviewed.
How offices and any physical assets are protected, and what you inherit from your cloud provider instead.
How devices and storage are wiped or destroyed when they leave, and how that is recorded.
The technical defences at the boundary and on laptops: firewalls, encryption in transit, endpoint protection and anti-malware.
How you detect new vulnerabilities and configuration drift, how you rank them, and the deadlines for fixing each severity.
What is logged, what raises an alert, and how someone decides whether an alert is actually a security event.
Who does what during a security incident, how customers and authorities are told, and how service is restored.
How code and infrastructure changes are reviewed, approved, tested and released, including emergency changes.
How the service survives and recovers from disruption, with the recovery targets you have committed to customers.
How subservice organisations and vendors are assessed before use and monitored afterwards, including reviewing their own reports.
Capacity headroom, redundancy and the recovery objectives behind any uptime commitment you have made.
What counts as confidential customer information, how it is handled, and when it is destroyed.
How you show that processing is complete, accurate and authorised — input validation, reconciliations and error handling.
What you tell individuals about their personal information and how you honour their choices about it.
Work that counts twice
SOC 2 (AICPA Trust Services Criteria) overlaps with 1 other framework in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.
Start SOC 2 today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.