Skip to content

Compliance & frameworks

SOC 2

SOC 2 — System and Organization Controls 2

SOC 2 is the trust report your customers, partners, and their auditors ask for. It attests that your controls over security — and optionally availability, confidentiality, processing integrity, and privacy — are designed and operating effectively. For a cloud-native company it is often the single most-requested piece of security evidence.

Who it applies to

SOC 2 is not a law — it is driven by the market. SaaS vendors, fintechs, and any company that processes customer data on behalf of enterprise buyers are pushed into SOC 2 by sales, procurement, and vendor-risk questionnaires. If enterprise deals stall on a security review, SOC 2 is usually the ask.

Cloud control themes

What SOC 2 asks of your cloud

  • Logical access controls (CC6) — identity, least privilege, MFA, deprovisioning
  • Change management (CC8) — how infrastructure and code changes are controlled
  • System monitoring (CC7) — logging, detection, and incident response
  • Risk management and vendor oversight (CC3, CC9)
  • Encryption and data protection for confidentiality

Domain × framework

Which assessment domains produce SOC 2 evidence

Assessment domainHow it maps
Identity & accessIAM findings map directly to CC6 logical-access controls — least privilege, MFA, and deprovisioning evidence.
Data securityEncryption and storage-exposure findings support confidentiality and CC6.1 data-protection criteria.
Network exposureNetwork segmentation and boundary findings evidence CC6.6 external-access controls.
Logging & monitoringLog coverage and detection findings map to CC7 system-monitoring criteria.
Configuration & postureBaseline and change-control findings support CC8 change management.

What you get

A findings report organized so it drops into your SOC 2 readiness: each cloud gap tied to the relevant Common Criteria, ranked by risk, with a remediation order your auditor and your engineers can both follow.

Most relevant to: FinTech, Healthcare, Commercial real estate

Questions

Is a health check the same as a SOC 2 audit?

No. A SOC 2 audit is performed by a licensed CPA firm. The health check is readiness work — it finds and prioritizes the cloud gaps that would otherwise surface during that audit, so you go in prepared.

Which Trust Services Criteria do you cover?

The cloud-technical side of Security (Common Criteria), plus Confidentiality and Availability where your environment touches them. Process-and-policy criteria are yours or your auditor’s domain.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check