SOC 2 (AICPA Trust Services Criteria): cited answers and gap reviews
SOC 2 reports on a service organization's controls against the AICPA Trust Services Criteria. Compliance Colleague helps with scoping, readiness and gap analysis for Type 1 and Type 2, and with reading a vendor's SOC 2 report, including carve-outs and complementary user entity controls.
What it covers
- Trust Services Criteria (2017, revised points of focus 2022): Security, Availability, Confidentiality, Processing Integrity and Privacy
- Common criteria CC1 to CC9 and the description criteria DC1 to DC9
- Type 1 and Type 2 scoping, readiness and evidence
- Subservice organizations: carve-out vs inclusive, CSOCs and CUECs
- SOC 1 vs SOC 2 vs SOC 3 vs SOC 2+
Questions you can ask
- “What evidence does CC6.1 expect for logical access in a Type 2 period?”
- “Our customer asked for a SOC 2. Do we need Availability as well as Security?”
- “How should we read a vendor's SOC 2 report that carves out its cloud provider?”
Every answer cites the SOC 2 requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- Your access control or change management policy checked against the common criteria
- A control matrix (Excel) checked for criteria with no control mapped
- A system description checked against DC1 to DC9
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk SOC 2 to other standards
With SOC 2 in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
Example answers
What it’s built from
Compliance Colleague works from our own clause-referenced material, checked against: 2017 Trust Services Criteria (With Revised Points of Focus – 2022) (AICPA). It cites the clause so you can check it against your own copy.
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More Global standards
PCI DSS · ISO 27001 · ISO 27701 · ISO 42001 · SWIFT CSP · WCAG
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.