SOC 2, finished by agents.
Agents collect the evidence behind all 51 Trust Services Criteria controls, draft the thirteen policies, run the tests and keep the window filled between audits.
51
controls
13
criteria groups
123
cross-mappings
13
policies
Collect once, count it twelve times.
SOC 2 carries 123 cross-mappings into the other eleven frameworks Zero2Do covers. Fifteen of them land straight on ISO 27001 and fifteen on HIPAA. Evidence an agent collects for CC6.1 lands on every control that asks the same question, with the gap between them written out rather than assumed away.
The policies, already drafted.
The policy writer drafts each document against the systems you connected, a second agent reviews it, and you approve. SOC 2 needs 13.
Information Security Policy
Establishes the overall security program, governance structure and security objectives.
Access Control Policy
Defines how user access is provisioned, reviewed and revoked across systems.
Incident Response Policy
Outlines procedures for detecting, responding to and recovering from security incidents.
Data Classification Policy
Sorts data into public, internal, confidential and restricted, then sets how each one is handled.
Data Retention & Disposal Policy
Specifies how long data is retained and the secure disposal procedures.
Encryption Policy
Defines encryption standards for data at rest and in transit.
Acceptable Use Policy
Defines acceptable and prohibited uses of company systems and resources.
Password Policy
Establishes password complexity, rotation and multi-factor authentication requirements.
Change Management Policy
Establishes how changes are requested, reviewed and implemented.
Secure Development Lifecycle Policy
Defines secure coding practices, code review and testing requirements.
Vendor Management Policy
Defines how third-party vendors are assessed, monitored and managed.
Risk Management Policy
Establishes the risk assessment methodology and the risk treatment process.
Business Continuity Policy
Outlines how the organization keeps operating during and after a disruption.
Before you start.
- Does Zero2Do handle Type I and Type II?
- Both. The same 51 controls back a Type I point-in-time report and a Type II observation window; for Type II the agents keep collecting on a schedule, so the window fills itself instead of being reconstructed at the end.
- Which Trust Services Criteria are covered?
- All five. Security is the common criteria set, CC1 through CC9; Availability, Confidentiality, Processing Integrity and Privacy sit alongside it, so you scope in only the categories your report commits to.
- Do we still need an auditor?
- Yes. Zero2Do prepares the audit, it does not issue the report. The audit room hands your CPA firm the evidence, the test results and the policy history in one place.
From zero to audit-ready in 30 days
Connect your systems and the SOC 2 controls start filling in on the first heartbeat.
- 01
Connect
Point Zero2Do at your cloud, code hosting and identity provider. Nothing to install.
- 02
Agents run
On a schedule, from day one: evidence gets collected against every control in scope, policies get drafted and tests get run.
- 03
Approve
You review what the agents produced and answer the few questions only you can answer.