Compliance & frameworks
SOC 2
SOC 2 — System and Organization Controls 2
SOC 2 is the trust report your customers, partners, and their auditors ask for. It attests that your controls over security — and optionally availability, confidentiality, processing integrity, and privacy — are designed and operating effectively. For a cloud-native company it is often the single most-requested piece of security evidence.
Who it applies to
SOC 2 is not a law — it is driven by the market. SaaS vendors, fintechs, and any company that processes customer data on behalf of enterprise buyers are pushed into SOC 2 by sales, procurement, and vendor-risk questionnaires. If enterprise deals stall on a security review, SOC 2 is usually the ask.
Cloud control themes
What SOC 2 asks of your cloud
- Logical access controls (CC6) — identity, least privilege, MFA, deprovisioning
- Change management (CC8) — how infrastructure and code changes are controlled
- System monitoring (CC7) — logging, detection, and incident response
- Risk management and vendor oversight (CC3, CC9)
- Encryption and data protection for confidentiality
Domain × framework
Which assessment domains produce SOC 2 evidence
| Assessment domain | How it maps |
|---|---|
| Identity & access | IAM findings map directly to CC6 logical-access controls — least privilege, MFA, and deprovisioning evidence. |
| Data security | Encryption and storage-exposure findings support confidentiality and CC6.1 data-protection criteria. |
| Network exposure | Network segmentation and boundary findings evidence CC6.6 external-access controls. |
| Logging & monitoring | Log coverage and detection findings map to CC7 system-monitoring criteria. |
| Configuration & posture | Baseline and change-control findings support CC8 change management. |
What you get
A findings report organized so it drops into your SOC 2 readiness: each cloud gap tied to the relevant Common Criteria, ranked by risk, with a remediation order your auditor and your engineers can both follow.
Most relevant to: FinTech, Healthcare, Commercial real estate
Questions
Is a health check the same as a SOC 2 audit?
No. A SOC 2 audit is performed by a licensed CPA firm. The health check is readiness work — it finds and prioritizes the cloud gaps that would otherwise surface during that audit, so you go in prepared.
Which Trust Services Criteria do you cover?
The cloud-technical side of Security (Common Criteria), plus Confidentiality and Availability where your environment touches them. Process-and-policy criteria are yours or your auditor’s domain.
Framework work in practice
Evidence rooms and compliance tables
Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.





