United States

SOC 2

61 controls. 196 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

61 controls 196 frameworks share controls with it United States held in the corpus

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

SOC 2 Evidence & Implementation Kit

61 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SOC2-A1.1Maintains capacity to meet availability commitments51
SOC2-A1.2Environmental protections, data backups, and recovery infrastructure support availability81
SOC2-A1.3Recovery plan procedures support system recovery from failures80
SOC2-C1.1Confidential information is identified and protected during receipt, processing, storage37
SOC2-C1.2Confidential information is disposed of securely28
SOC2-CC1.1COSO principle 1: Demonstrates commitment to integrity and ethical values24
SOC2-CC1.2COSO principle 2: Board exercises oversight responsibility23
SOC2-CC1.3COSO principle 3: Management establishes structures, reporting lines, and authorities34
SOC2-CC1.4COSO principle 4: Demonstrates commitment to attract and retain competent individuals38
SOC2-CC1.5COSO principle 5: Holds individuals accountable for internal control responsibilities32
SOC2-CC2.1COSO principle 13: Obtains and generates relevant, quality information29
SOC2-CC2.2COSO principle 14: Internally communicates information including objectives and responsibilities33
SOC2-CC2.3COSO principle 15: Communicates with external parties regarding matters affecting controls33
SOC2-CC3.1COSO principle 6: Specifies objectives to identify and assess risks29
SOC2-CC3.2COSO principle 7: Identifies risks and analyzes to determine how managed40
SOC2-CC3.3COSO principle 8: Considers potential for fraud17
SOC2-CC3.4COSO principle 9: Identifies and assesses changes that could impact internal controls33
SOC2-CC4.1COSO principle 16: Selects and develops ongoing and separate evaluations40
SOC2-CC4.2COSO principle 17: Evaluates and communicates deficiencies in a timely manner128
SOC2-CC5.1COSO principle 10: Selects and develops control activities to mitigate risks31
SOC2-CC5.2COSO principle 11: Selects and develops general controls over technology34
SOC2-CC5.3COSO principle 12: Deploys control activities through policies and procedures32
SOC2-CC6.1Implements logical access security software, infrastructure and architectures over protected information assets51
SOC2-CC6.2Prior to granting access, registration and authorization processes are established61
SOC2-CC6.3Role-based access and least privilege are enforced93
SOC2-CC6.4Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized p28
SOC2-CC6.5Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longe26
SOC2-CC6.6Measures against threats outside system boundaries are implemented33
SOC2-CC6.7Transmission of data is restricted to authorized users33
SOC2-CC6.8Controls to prevent or detect unauthorized or malicious software36
SOC2-CC7.1Detection and monitoring procedures for security events are in place38
SOC2-CC7.2Monitors system components for anomalies indicating malicious acts37
SOC2-CC7.3Evaluates security events to determine incident status34
SOC2-CC7.4Responds to identified security incidents through defined procedures155
SOC2-CC7.5Identifies the root cause of security incidents91
SOC2-CC8.1Change management processes are in place58
SOC2-CC9.1Identifies, selects and develops risk mitigation activities36
SOC2-CC9.2Risk mitigation activities include assessment of vendor and business partner controls38
SOC2-P1.1Privacy notice provides clear notice about privacy practices16
SOC2-P2.1Consent is obtained for the collection, use, and disclosure of personal information13
SOC2-P3.1Personal information is collected consistent with privacy commitments68
SOC2-P3.2Explicit consent is obtained for sensitive personal information13
SOC2-P4.1Personal information is used for purposes identified in privacy commitments17
SOC2-P4.2Personal information is retained for only as long as needed23
SOC2-P4.3Personal information is securely disposed of76
SOC2-P5.1Personal information is accessed only by authorized personnel24
SOC2-P5.2Corrections to personal information are processed timely12
SOC2-P6.1Personal information is disclosed to third parties only as committed60
SOC2-P6.2Records of personal information disclosures are maintained24
SOC2-P6.3Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objec26
SOC2-P6.4Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses tho27
SOC2-P6.5Obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of pe24
SOC2-P6.6Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy29
SOC2-P6.7Provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the e11
SOC2-P7.1Personal information collected is limited to what is necessary and relevant15
SOC2-P8.1Inquiries, complaints, and disputes regarding personal information are addressed14
SOC2-PI1.1Obtains or generates and uses relevant quality information to support processing integrity18
SOC2-PI1.2System inputs are complete, accurate, and processed in a timely manner14
SOC2-PI1.3System processing is complete, valid, accurate, timely, and authorized16
SOC2-PI1.4System outputs are complete, valid, accurate, timely, and distributed13
SOC2-PI1.5Inputs are processed completely, accurately, and timely for stored data17

Tell me when SOC 2 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Privacy notice published and versioned
  • Consent capture and revocation records
  • Data subject access request log
  • Retention and disposal schedule for personal information
  • Third party disclosure register
  • Privacy notice and versioning

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for SOC 2, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition