A SOC 1 report is delivered as a package whose sections the held reports show in the same order: the independent service auditor's report with the opinion and, for type 2, a description of the tests performed and their results (or a pointer to that section); management's assertion; the description of the system; the control objectives with the related controls and, for a type 2 report, the auditor's tests and the results of each; and, where included, further information the service organisation supplies that falls outside the opinion; the report identifies the description, the function, the period or date, the criteria, any uncovered information and any subservice organisation with the carve-out or inclusive statements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.