SOC 2 compliance automation
SOC 2 is an examination of a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, reported by an independent CPA against the AICPA's Trust Services Criteria (AICPA & CIMA). A Type 1 report addresses the design of controls at a point in time; a Type 2 report also covers how they operated over a period, which is where automated, dated evidence pays off.
SOC 2 controls in our map
21 controls carry a SOC 2 reference; 19 of them can be evidenced from systems you probably already run. The references are to the criteria (CC1 to CC9, the common criteria, and A1 for availability); control wording is our own.
| Control | SOC 2 criteria | Evidence from | ISO 27001 | HIPAA |
|---|---|---|---|---|
| SEC-POL Security policies approved and acknowledged | CC5.3 | HR system | A.5.1 | §164.316(a), §164.316(b)(1) |
| ROLES Security and AI roles assigned | CC1.3 | HR system | A.5.2 | §164.308(a)(2) |
| RISK Risk assessment and treatment | CC3.1, CC3.2 | Ticketing and change tracking | 6.1.2, 6.1.3, 8.2 | §164.308(a)(1)(ii)(A), §164.308(a)(1)(ii)(B) |
| ASSETS Asset inventory | CC6.1 | Cloud platform, Device management and endpoint protection | A.5.9 | §164.310(d)(1) |
| ACCESS Least-privilege access, approved before it is granted | CC6.2, CC6.3 | Identity provider or SSO, Ticketing and change tracking | A.5.15, A.5.18, A.8.2 | §164.308(a)(4), §164.312(a)(1) |
| MFA Unique accounts and multi-factor authentication | CC6.1 | Identity provider or SSO | A.5.17, A.8.5 | §164.312(a)(2)(i), §164.312(d) |
| OFFBOARD Access removed when people leave | CC6.2 | HR system, Identity provider or SSO | A.5.11, A.5.18 | §164.308(a)(3)(ii)(C) |
| ACCESS-REVIEW Periodic access reviews | CC6.3 | Identity provider or SSO | A.5.18 | §164.308(a)(4)(ii)(C) |
| ENCRYPT Encryption at rest and in transit | CC6.1, CC6.7 | Cloud platform, Device management and endpoint protection | A.8.24 | §164.312(a)(2)(iv), §164.312(e)(1) |
| ENDPOINT Endpoint protection | CC6.8 | Device management and endpoint protection | A.8.1, A.8.7 | §164.308(a)(5)(ii)(B) |
| VULN Vulnerability management | CC7.1 | Vulnerability scanner, Cloud platform, Code repository and CI/CD | A.8.8 | §164.308(a)(1)(ii)(B) |
| LOGGING Logging and monitoring | CC7.2 | Central logging or SIEM, Cloud platform | A.8.15, A.8.16 | §164.312(b), §164.308(a)(1)(ii)(D) |
| INCIDENT Incident response | CC7.3, CC7.4 | Ticketing and change tracking | A.5.24, A.5.25, A.5.26 | §164.308(a)(6) |
| CHANGE Change management | CC8.1 | Code repository and CI/CD, Ticketing and change tracking | A.8.32 | – |
| SDLC Secure development | CC8.1 | Code repository and CI/CD | A.8.25, A.8.28, A.8.31 | – |
| BACKUP Backups and restore tests | A1.2, A1.3 | Backup service, Cloud platform | A.8.13 | §164.308(a)(7)(ii)(A) |
| BCDR Business continuity and disaster recovery | A1.3, CC9.1 | Manual | A.5.29, A.5.30 | §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(D) |
| VENDOR Vendor and AI supplier risk | CC9.2 | Vendor inventory | A.5.19, A.5.20, A.5.22 | §164.308(b)(1) |
| TRAINING Security and AI awareness training | CC2.2 | Security awareness training platform, HR system | A.6.3 | §164.308(a)(5)(i) |
| SCREENING Screening and confidentiality agreements | CC1.4 | HR system | A.6.1, A.6.2, A.6.6 | §164.308(a)(3)(ii)(B) |
| AUDIT Internal audit and management review | CC4.1 | Manual | 9.2, 9.3 | §164.308(a)(8) |
Where automation helps most in a Type 2 period
- Access (CC6): MFA enforcement, joiners and leavers matched to HR, and quarterly access reviews are sampled across the whole period.
- Operations (CC7): vulnerability scans and log alerts produce dated records continuously.
- Change management (CC8): pull-request approvals and deployment records come straight from the code host.
What stays manual for SOC 2
Risk assessment decisions, vendor reviews, continuity tests and internal evaluation produce evidence through people. Schedule them early: a missed quarterly review can't be recreated after the period ends.
Planning more than SOC 2? See compliance control mapping and what a platform automates.
Sources
Questions
What is SOC 2?
An examination by an independent CPA of a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, reported against the AICPA's Trust Services Criteria.
Which SOC 2 criteria are easiest to automate?
Logical access (CC6), system operations and monitoring (CC7) and change management (CC8), because the evidence lives in identity, cloud, logging and code systems.
Does SOC 2 evidence help with ISO 27001?
Yes. Most controls that answer SOC 2 also answer ISO/IEC 27001 Annex A; the table on this page shows the reference for each.