Skip to main content
—
Framework library
Framework module · soc-2-type-ii

SOC 2

Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

2017 TSC (revised points of focus, 2022) · AICPA — Trust Services Criteria (TSP section 100)

Standing today
Implemented
9 evidence lanes · 33 control units

00Answer

from the registry record
What is SOC 2?
Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
Who does SOC 2 apply to?
SOC 2 applies to technology, SaaS, service organizations, US, global, per AICPA — Trust Services Criteria (TSP section 100).
What is the current version of SOC 2?
The current edition is 2017 TSC (revised points of focus, 2022), issued by AICPA — Trust Services Criteria (TSP section 100). Source: https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022.
What does an assessment under SOC 2 require?
33 control units are on record (33 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.), organized into 5 control families: Security, Availability, Confidentiality, Processing integrity, Privacy.

01Standing

Implemented

A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.

Blueprint with 9 evidence lanes. 4 of 4 registered test plans run against a real target.

Engagement
SOC 2 readiness — Security category
Control set
33 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
Native identifiers
Trust Services Criteria identifiers CC1.1 through CC9.2. Optional category criteria (A1, C1, PI1, P1-P8) are out of scope for this blueprint.
Evidence lanes
  1. 01CC1 — Control Environmentcode of conduct and acknowledgments · board or governance minutes · org chart and role definitions · training completion records
  2. 02CC2 — Communication and Informationpublished policy set · system and data flow documentation · customer-facing commitments
  3. 03CC3 — Risk Assessmentrisk register · fraud risk analysis · change-triggered risk reassessments
  4. 04CC4 — Monitoring Activitiescontrol testing results · penetration test report · findings register with remediation
  5. 05CC5 — Control Activitiesrisk-to-control mapping · technology general control documentation · policy approval records
  6. 06CC6 — Logical and Physical Access Controlsidentity provider configuration export · access review records · encryption and key management evidence · endpoint protection coverage
  7. 07CC7 — System Operationsvulnerability scan results · monitoring and alert records · incident tickets · backup and recovery test results
  8. 08CC8 — Change Managementchange tickets or pull requests with approvals · test evidence · deployment records
  9. 09CC9 — Risk Mitigationbusiness continuity and disaster recovery plans and exercises · vendor inventory and due diligence · subservice organization reports

02Registry record

checked 2026-08-30
Registry status
Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
Control units
3333 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
Control families
Security · Availability · Confidentiality · Processing integrity · Privacy
Applies to
technology · SaaS · service organizations · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

1 edition
2017 TSC (revised points of focus, 2022)Current editiondate not published

06Related frameworks

scored from registry facts
  1. Also applies to technology · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. AIUC-1Q3 2026 (2026-07-15 release)

    Also applies to technology · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.

  3. Also applies to SaaS · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.

  4. Also applies to SaaS · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

SOC 2 | ControlFrame