SOC 2
Trust Service Criteria for service organizations covering security, availability, processing integrity, confidentiality, and privacy
SOC 2 is a compliance framework from United States with 5 domains and 61 controls that map to 194 other frameworks. The largest domains are CC - Common Criteria (Security) (33 controls), P - Privacy (18 controls), PI - Processing Integrity (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
A - Availability
Systems are available for operation and use as committed or agreed
C - Confidentiality
Information designated as confidential is protected as committed or agreed
CC - Common Criteria (Security)
Control criteria applicable to all trust service categories
| Code | Title |
|---|---|
| SOC2-CC1.1 | COSO principle 1: Demonstrates commitment to integrity and ethical values |
| SOC2-CC1.2 | COSO principle 2: Board exercises oversight responsibility |
| SOC2-CC1.3 | COSO principle 3: Management establishes structures, reporting lines, and authorities |
| SOC2-CC1.4 | COSO principle 4: Demonstrates commitment to attract and retain competent individuals |
| SOC2-CC1.5 | COSO principle 5: Holds individuals accountable for internal control responsibilities |
| SOC2-CC2.1 | COSO principle 13: Obtains and generates relevant, quality information |
| SOC2-CC2.2 | COSO principle 14: Internally communicates information including objectives and responsibilities |
| SOC2-CC2.3 | COSO principle 15: Communicates with external parties regarding matters affecting controls |
| SOC2-CC3.1 | COSO principle 6: Specifies objectives to identify and assess risks |
| SOC2-CC3.2 | COSO principle 7: Identifies risks and analyzes to determine how managed |
| SOC2-CC3.3 | COSO principle 8: Considers potential for fraud |
| SOC2-CC3.4 | COSO principle 9: Identifies and assesses changes that could impact internal controls |
| SOC2-CC4.1 | COSO principle 16: Selects and develops ongoing and separate evaluations |
| SOC2-CC4.2 | COSO principle 17: Evaluates and communicates deficiencies in a timely manner |
| SOC2-CC5.1 | COSO principle 10: Selects and develops control activities to mitigate risks |
| SOC2-CC5.2 | COSO principle 11: Selects and develops general controls over technology |
| SOC2-CC5.3 | COSO principle 12: Deploys control activities through policies and procedures |
| SOC2-CC6.1 | Implements logical access security software, infrastructure and architectures over protected information assets |
| SOC2-CC6.2 | Prior to granting access, registration and authorization processes are established |
| SOC2-CC6.3 | Role-based access and least privilege are enforced |
| SOC2-CC6.4 | Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives |
| SOC2-CC6.5 | Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's |
| SOC2-CC6.6 | Measures against threats outside system boundaries are implemented |
| SOC2-CC6.7 | Transmission of data is restricted to authorized users |
| SOC2-CC6.8 | Controls to prevent or detect unauthorized or malicious software |
| SOC2-CC7.1 | Detection and monitoring procedures for security events are in place |
| SOC2-CC7.2 | Monitors system components for anomalies indicating malicious acts |
| SOC2-CC7.3 | Evaluates security events to determine incident status |
| SOC2-CC7.4 | Responds to identified security incidents through defined procedures |
| SOC2-CC7.5 | Identifies the root cause of security incidents |
| SOC2-CC8.1 | Change management processes are in place |
| SOC2-CC9.1 | Identifies, selects and develops risk mitigation activities |
| SOC2-CC9.2 | Risk mitigation activities include assessment of vendor and business partner controls |
P - Privacy
Personal information is collected, used, retained, disclosed, and disposed according to commitments
| Code | Title |
|---|---|
| SOC2-P1.1 | Privacy notice provides clear notice about privacy practices |
| SOC2-P2.1 | Consent is obtained for the collection, use, and disclosure of personal information |
| SOC2-P3.1 | Personal information is collected consistent with privacy commitments |
| SOC2-P3.2 | Explicit consent is obtained for sensitive personal information |
| SOC2-P4.1 | Personal information is used for purposes identified in privacy commitments |
| SOC2-P4.2 | Personal information is retained for only as long as needed |
| SOC2-P4.3 | Personal information is securely disposed of |
| SOC2-P5.1 | Personal information is accessed only by authorized personnel |
| SOC2-P5.2 | Corrections to personal information are processed timely |
| SOC2-P6.1 | Personal information is disclosed to third parties only as committed |
| SOC2-P6.2 | Records of personal information disclosures are maintained |
| SOC2-P6.3 | Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which |
| SOC2-P6.4 | Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed |
| SOC2-P6.5 | Obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to |
| SOC2-P6.6 | Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy |
| SOC2-P6.7 | Provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy |
| SOC2-P7.1 | Personal information collected is limited to what is necessary and relevant |
| SOC2-P8.1 | Inquiries, complaints, and disputes regarding personal information are addressed |
PI - Processing Integrity
System processing is complete, valid, accurate, timely, and authorized
| Code | Title |
|---|---|
| SOC2-PI1.1 | Obtains or generates and uses relevant quality information to support processing integrity |
| SOC2-PI1.2 | System inputs are complete, accurate, and processed in a timely manner |
| SOC2-PI1.3 | System processing is complete, valid, accurate, timely, and authorized |
| SOC2-PI1.4 | System outputs are complete, valid, accurate, timely, and distributed |
| SOC2-PI1.5 | Inputs are processed completely, accurately, and timely for stored data |
Your Compliance Coverage
If you comply with SOC 2, you already cover:
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
100%
61 controls mapped
Compare →NIST SP 800-53 Rev 5
100%
61 controls mapped
Compare →ISO 27001:2022
98%
60 controls mapped
Compare →+ 191 more: ISO 27701:2019 (97%), ISO 27002:2022 (97%)
See all 194 mapped frameworks ↓Maps to 194 other frameworks
What is SOC 2 and who does it apply to?
SOC 2 is a compliance framework from United States with 5 domains and 61 controls. Trust Service Criteria for service organizations covering security, availability, processing integrity, confidentiality, and privacy It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does SOC 2 actually require?
SOC 2 has 61 controls organised across 5 domains. The largest domains are CC - Common Criteria (Security) (33 controls), P - Privacy (18 controls), PI - Processing Integrity (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of SOC 2 do I already cover?
SOC 2 maps to 194 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (100% coverage), NIST SP 800-53 Rev 5 (100% coverage), ISO 27001:2022 (98% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement SOC 2?
Start your SOC 2 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SOC 2 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 61 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required