SOC 2
Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
2017 TSC (revised points of focus, 2022) · AICPA — Trust Services Criteria (TSP section 100)
00Answer
01Standing
A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.
Blueprint with 9 evidence lanes. 4 of 4 registered test plans run against a real target.
- Engagement
- SOC 2 readiness — Security category
- Control set
- 33 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
- Native identifiers
- Trust Services Criteria identifiers CC1.1 through CC9.2. Optional category criteria (A1, C1, PI1, P1-P8) are out of scope for this blueprint.
- Evidence lanes
- 01CC1 — Control Environmentcode of conduct and acknowledgments · board or governance minutes · org chart and role definitions · training completion records
- 02CC2 — Communication and Informationpublished policy set · system and data flow documentation · customer-facing commitments
- 03CC3 — Risk Assessmentrisk register · fraud risk analysis · change-triggered risk reassessments
- 04CC4 — Monitoring Activitiescontrol testing results · penetration test report · findings register with remediation
- 05CC5 — Control Activitiesrisk-to-control mapping · technology general control documentation · policy approval records
- 06CC6 — Logical and Physical Access Controlsidentity provider configuration export · access review records · encryption and key management evidence · endpoint protection coverage
- 07CC7 — System Operationsvulnerability scan results · monitoring and alert records · incident tickets · backup and recovery test results
- 08CC8 — Change Managementchange tickets or pull requests with approvals · test evidence · deployment records
- 09CC9 — Risk Mitigationbusiness continuity and disaster recovery plans and exercises · vendor inventory and due diligence · subservice organization reports
02Registry record
- Registry status
- Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
- Control units
- 3333 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
- Control families
- Security · Availability · Confidentiality · Processing integrity · Privacy
- Applies to
- technology · SaaS · service organizations · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| 2017 TSC (revised points of focus, 2022) | Current edition | date not published |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to technology · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- AIUC-1Q3 2026 (2026-07-15 release)
Also applies to technology · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.
Also applies to SaaS · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.
- ISO/IEC 270182025
Also applies to SaaS · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.