Skip to main content
LiveGlobal

SOC 2

SOC 2 — AICPA Trust Services Criteria

The AICPA trust standard enterprise buyers ask for — managed end to end, audit-ready.

Overview

What is SOC 2?

SOC 2 is an attestation report produced by a licensed CPA firm against the AICPA Trust Services Criteria. It is not a certification or a law — a qualified auditor examines your controls and issues an opinion that customers and their security teams rely on. It has become the default security assurance ask for SaaS and service providers selling into North America and, increasingly, worldwide.

Every SOC 2 report covers the mandatory Security category — the 33 Common Criteria (CC1–CC9), built on the COSO framework, spanning the control environment, communication, risk assessment, monitoring, logical and physical access, system operations, change management and vendor risk. You then optionally add any of four further categories — Availability, Confidentiality, Processing Integrity and Privacy — depending on the promises you make to customers.

There are two report types. A Type I opinion assesses whether your controls are suitably designed at a single point in time; a Type II opinion — the one most buyers want — tests whether those controls actually operated effectively across a period, typically three to twelve months. Type II therefore rewards continuous evidence: access reviews run, incidents handled, changes approved, vendors assessed — accumulated over the window, not assembled the week before.

A SOC 2 report also contains a written "Description of the System" — your infrastructure, software, people, data, processes and the commitments you make — which has no GDPR or ISO equivalent. Audulate is honest about the split: it auto-derives the technical Common Criteria evidence it can scan, gives you structured attestation surfaces for the organisational controls, and a workspace to declare your scope and system description.

Applicability

Who must comply?

  • No organisation is legally required to hold a SOC 2 report — but it is increasingly a commercial prerequisite, demanded by enterprise customers, procurement teams and partners before they will buy.
  • SaaS and technology companies selling to larger organisations, where a SOC 2 Type II report short-cuts lengthy security questionnaires and vendor due diligence.
  • Service providers, processors and data centres that handle customer data and need to evidence an independently-examined security baseline.
  • Businesses with 50+ employees or enterprise clients, where a recognised trust attestation accelerates sales and renewals.
  • Teams already pursuing ISO 27001, since the Common Criteria map closely onto the ISO Annex A controls — most of the evidence is shared.

Obligations

What you must maintain

A defined scope of examination

Which Trust Services categories are in scope (Security always; plus any of Availability, Confidentiality, Processing Integrity, Privacy) and the Type I / Type II choice.

A "Description of the System"

The written narrative of your infrastructure, software, people, data, processes and the commitments you make to customers — a required SOC 2 report section.

Control environment & governance

Policies, assigned roles and accountability that satisfy the COSO-based Common Criteria CC1–CC5 (integrity, communication, risk assessment, monitoring, control activities).

Logical & physical access controls

Authentication, least-privilege access, provisioning/deprovisioning, encryption and boundary protection across CC6.

System operations & change management

Vulnerability detection, monitoring, incident response and authorised, tested changes across CC7 and CC8.

Vendor & business-partner risk

Assessed sub-processors with agreements and ongoing monitoring (CC9.2) — a frequent SOC 2 finding.

Continuous Type II evidence

Access reviews, incidents, changes and vendor assessments accumulated across the examination period — not assembled at the end.

Coverage

How Audulate covers SOC 2

Attested

Audit-ready Trust Services control set

The Common Criteria mapped onto one control set, backed by the same modules ISO 27001 uses — so the security evidence is shared, not duplicated.

  • The 33 Common Criteria (CC1–CC9) mapped onto your control catalogue, plus five Processing Integrity controls (PI1.1–PI1.5) when that category is in scope.
  • Scope-of-examination workspace: declare your in-scope categories, Type I / II, and the Description of the System.
  • Risk register, policy library with magic-link staff acknowledgement, periodic access reviews and vendor risk assessments (CC9.2).
  • Incident register, training records and asset inventory — the operational evidence a Type II period requires.
Automated scan

Automated evidence where we can scan

The technical Common Criteria (CC6 / CC7) get auto-derived evidence from your website, cloud and code scans — so the technical controls fill themselves in.

  • Encryption in transit, security headers, CSP, SRI and mixed-content from web scans (CC6.1, CC6.6, CC6.7).
  • Outdated-dependency and vulnerability signals feeding CC7.1.
  • Cloud posture and environment separation from infrastructure scans.
  • Secrets and insecure patterns caught in pull requests feed the change-management controls (CC8).
Attested

Shared with ISO 27001 & GDPR

Because the Common Criteria overlap heavily with ISO Annex A and GDPR Art. 32, evidence you create once counts across frameworks.

  • DPAs, RoPA, breach register, staff training and transfer safeguards cross-tag to both SOC 2 and ISO 27001.
  • The same compliance score and evidence trail feed every framework you enable.
  • Run SOC 2 and ISO 27001 together and most of the control work is shared, not repeated.

Automated technical controls feed the same compliance score and evidence trail as your other frameworks; the rest is tracked as audit-ready status on your control set.

Get started

Up and running in 3 steps

1

Run a free scan

Start with a website scan — the technical Common Criteria (CC6 / CC7) begin populating immediately.

2

Set your scope & controls

Declare your in-scope categories and Description of the System, then set status and owners across the control set.

3

Build Type II evidence

Keep access reviews, incidents, changes and vendor assessments current across the examination period, ready for your CPA.

FAQ

SOC 2 questions

Does Audulate make me SOC 2 certified?

No — SOC 2 is not a certification. It is an attestation report issued only by a licensed CPA firm after they examine your controls. Audulate is the audit-ready toolkit that gets you there: it auto-derives the technical evidence it can scan, gives you structured surfaces for the organisational controls, and a workspace for your scope and Description of the System — so your auditor has organised evidence to examine.

What is the difference between SOC 2 Type I and Type II?

A Type I report assesses whether your controls are suitably designed at a single point in time. A Type II report — the one most enterprise buyers want — tests whether those controls operated effectively over a period, usually three to twelve months. Type II rewards continuous evidence, which is exactly what Audulate is built to accumulate.

Which Trust Services categories do I need?

Security (the Common Criteria, CC1–CC9) is mandatory in every SOC 2 report. You then add any of Availability, Confidentiality, Processing Integrity and Privacy based on the commitments you make to customers. Audulate lets you declare your in-scope categories and renders the relevant criteria — for example the Processing Integrity controls only appear when you scope that category in.

How much of SOC 2 is automated?

Most of SOC 2 is organisational. Audulate auto-derives evidence for the technical Common Criteria it can observe via website, cloud and code scans (encryption, headers, CSP, SRI, vulnerabilities, change signals), and provides attestation and evidence surfaces for the rest. We don’t claim to auto-check controls we can’t actually see.

Can I do SOC 2 and ISO 27001 together?

Yes, and they reinforce each other heavily. The SOC 2 Common Criteria map closely onto ISO 27001 Annex A, so most controls and evidence are shared. Audulate reuses the same control set, scans and modules for both — enable them together and you do the work once.

This page is informational and not legal advice. Coverage describes Audulate’s current capabilities; your compliance obligations depend on your specific circumstances.

Get started today

Your compliance changes
every time you ship.

Audulate keeps up. Free to start.

2 free scans / monthNo credit card5-minute setup