← All resources
SOC 24 min read

Work through the SOC 2 checklist

The five Trust Services Criteria, what each one asks of you, and which parts the agents carry.

SOC 2 is not a list of technologies to buy. It is a report in which an auditor says your controls were described honestly and were operating. This guide walks the five Trust Services Criteria, what each asks of you, and which parts of the work the agents carry.

Type I or Type II

A Type I report is a point in time: the controls exist and are designed properly on a given day. A Type II covers a window, usually three to twelve months. It asks whether the controls kept operating throughout. Type II is what customers ask for, and it is decided by evidence collected across the whole period, not assembled at the end of it.

Scope first

  • Name the system: the product, its infrastructure, and the people who operate it.
  • Choose your criteria. Security is required of everyone; the other four are included only where you make a promise about them.
  • Set the window, and start collecting on day one of it rather than the last week.

Security: the common criteria

The one category no report omits, and the largest. It covers governance, access, change management, monitoring and response.

  • Policies approved, published, and acknowledged by everyone who has to follow them.
  • Access granted on a documented approval, reviewed on a schedule, revoked on exit.
  • Multi-factor authentication on administrative and remote access.
  • Changes reviewed and tested before they reach production.
  • Logging and alerting in place, with an incident response plan that has been exercised.
  • Vendors assessed before they hold your data, and reassessed while they still do.
  • Risks assessed at least annually, with owners and dates on what you decided to fix.

Availability

Include it when you commit to uptime.

  • Capacity and performance monitored against the thresholds you promised.
  • Backups running, and restores tested. The restore is the half that gets missed.
  • A recovery plan with a stated objective, and a test of it on the record.

Processing integrity

Include it when customers rely on your system to process their work correctly.

  • Inputs validated; errors caught, queued and resolved rather than dropped.
  • Processing monitored for completeness and accuracy end to end.
  • Outputs reconciled against what came in.

Confidentiality

Include it when you hold information a contract says you will protect.

  • Data classified, and the classification visible where people handle it.
  • Encryption in transit and at rest, with keys managed and rotated.
  • Retention and disposal that actually run, on a schedule you can evidence.

Privacy

Include it when you handle personal information about individuals.

  • A notice that matches what you really collect and why.
  • Consent captured and revocable, with the record kept.
  • A path for access, correction and deletion requests, and a log of how each was handled.

What the agents carry

Most of that list is collection, drafting and testing on a schedule. That is exactly what the agents do. They pull configuration and access records out of your cloud, code hosting and identity provider, draft the policies SOC 2 requires against your environment, have a second agent review each draft, run the control tests that can be automated, chase acknowledgments, and file everything into the audit room by control.

What is left for you is judgment: approving a policy, confirming an exception, deciding what a risk is worth. Because a Type II is decided by the whole window, the agents keep collecting between audits rather than only ahead of one.

Cross-mapping

SOC 2 is rarely the last framework anyone needs. The 422 cross-mappings in the platform mean an access review evidenced once here also answers its ISO 27001 and HIPAA equivalents, so the second framework costs a fraction of the first. See SOC 2 on the platform for the control counts, or the evidence guide for what your auditor will accept.