Framework module · soc-2-type-ii
SOC 2
Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
2017 TSC (revised points of focus, 2022) · AICPA — Trust Services Criteria (TSP section 100)
Standing today
Implemented
9 evidence lanes · 33 control units
01Standing
Implemented
A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.
Blueprint with 9 evidence lanes. 4 of 4 registered test plans run against a real target.
- Engagement
- SOC 2 readiness — Security category
- Control set
- 33 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
- Native identifiers
- Trust Services Criteria identifiers CC1.1 through CC9.2. Optional category criteria (A1, C1, PI1, P1-P8) are out of scope for this blueprint.
- Evidence lanes
- 01CC1 — Control Environmentcode of conduct and acknowledgments · board or governance minutes · org chart and role definitions · training completion records
- 02CC2 — Communication and Informationpublished policy set · system and data flow documentation · customer-facing commitments
- 03CC3 — Risk Assessmentrisk register · fraud risk analysis · change-triggered risk reassessments
- 04CC4 — Monitoring Activitiescontrol testing results · penetration test report · findings register with remediation
- 05CC5 — Control Activitiesrisk-to-control mapping · technology general control documentation · policy approval records
- 06CC6 — Logical and Physical Access Controlsidentity provider configuration export · access review records · encryption and key management evidence · endpoint protection coverage
- 07CC7 — System Operationsvulnerability scan results · monitoring and alert records · incident tickets · backup and recovery test results
- 08CC8 — Change Managementchange tickets or pull requests with approvals · test evidence · deployment records
- 09CC9 — Risk Mitigationbusiness continuity and disaster recovery plans and exercises · vendor inventory and due diligence · subservice organization reports
02Registry record
checked 2026-08-06
- Registry status
- Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
- Control units
- 3333 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
- Control families
- Security · Availability · Confidentiality · Processing integrity · Privacy
- Applies to
- technology · SaaS · service organizations · US · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
03Version ledger
1 edition
| 2017 TSC (revised points of focus, 2022) | Current edition | date not published |