SOC 2, criterion by criterion
One deep guide per category: what each criterion demands, the exceptions auditors actually write, and the evidence they sample across a Type II period. Reports are issued by licensed CPA firms — we get you ready and coordinate the examination.
The mandatory category — every SOC 2 examination includes the Common Criteria, whatever else is in scope. CC1–…
Three criteria with heavy operational implications: capacity, environmental protections and backup, and tested…
The category for systems whose value IS the correctness of processing — payments, payroll, billing, data pipel…
Two criteria, deceptively simple: identify and protect confidential information, then dispose of it provably. …
The largest optional category: eight criteria tracking personal information from notice to enforcement. Scoped…
Start with the free self-assessment, or go straight to SOC 2 services.
