Framework library
Framework module · soc-2-type-ii

SOC 2

Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

2017 TSC (revised points of focus, 2022) · AICPA — Trust Services Criteria (TSP section 100)

Standing today
Implemented
9 evidence lanes · 33 control units

01Standing

Implemented

A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.

Blueprint with 9 evidence lanes. 4 of 4 registered test plans run against a real target.

Engagement
SOC 2 readiness — Security category
Control set
33 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
Native identifiers
Trust Services Criteria identifiers CC1.1 through CC9.2. Optional category criteria (A1, C1, PI1, P1-P8) are out of scope for this blueprint.
Evidence lanes
  1. 01CC1 — Control Environmentcode of conduct and acknowledgments · board or governance minutes · org chart and role definitions · training completion records
  2. 02CC2 — Communication and Informationpublished policy set · system and data flow documentation · customer-facing commitments
  3. 03CC3 — Risk Assessmentrisk register · fraud risk analysis · change-triggered risk reassessments
  4. 04CC4 — Monitoring Activitiescontrol testing results · penetration test report · findings register with remediation
  5. 05CC5 — Control Activitiesrisk-to-control mapping · technology general control documentation · policy approval records
  6. 06CC6 — Logical and Physical Access Controlsidentity provider configuration export · access review records · encryption and key management evidence · endpoint protection coverage
  7. 07CC7 — System Operationsvulnerability scan results · monitoring and alert records · incident tickets · backup and recovery test results
  8. 08CC8 — Change Managementchange tickets or pull requests with approvals · test evidence · deployment records
  9. 09CC9 — Risk Mitigationbusiness continuity and disaster recovery plans and exercises · vendor inventory and due diligence · subservice organization reports

02Registry record

checked 2026-08-06
Registry status
Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
Control units
3333 common criteria across nine series (Security category only). ControlFrame criteria index — criterion identifiers from AICPA TSP section 100; titles and guidance are ControlFrame's wording, not AICPA verbatim text. Optional categories are omitted rather than stubbed.
Control families
Security · Availability · Confidentiality · Processing integrity · Privacy
Applies to
technology · SaaS · service organizations · US · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06

03Version ledger

1 edition
2017 TSC (revised points of focus, 2022)Current editiondate not published
SOC 2 — framework module | ControlFrame