SOC 2 Assurance
Trust Services Criteria readiness for service organisations, end to end — from scoping the system description to the evidence an auditor will sample over the observation period.
- CriteriaSecurity + Availability, Processing Integrity, Confidentiality, Privacy
- Report typesType 1 (point in time) · Type 2 (period)
- IssuerAICPA — reports by a licensed CPA firm
- ObservationTypically 6–12 months for Type 2
SOC 2 Assurance
SOC 2 is how a service organisation proves to its customers that the controls protecting their data actually operate. A Type 1 report describes the controls at a point in time; a Type 2 report has an auditor test them over an observation period — which is where most programmes discover that a control which exists on paper was not operating every week.
The work is evidence, on a calendar. Access reviews, change approvals, backup tests, vendor reviews and incident records have to happen on schedule and leave a record the auditor can sample. Teams that treat SOC 2 as a document exercise arrive at the audit with policies and no population.
GRCLens runs SOC 2 as a continuous programme: the Trust Services Criteria are mapped to the common control model, recurring evidence is scheduled and collected as it happens, and every control shows its coverage of the observation period before the auditor asks.
What the platform does for SOC 2
Criteria mapped, not copied
The Common Criteria and the optional categories map to controls already evidenced for ISO/IEC 27001 and ISO/IEC 20000, so a service organisation with either standard starts well above zero.
Evidence, dated, per control
Access reviews, change tickets and restore tests are attached to the control with their date, so what was collected during the observation period — and what was not — is visible before the auditor asks.
System Description and Management Assertion
Both held as documents in the SOC 2 foundation module — scope, boundaries, sub-service organisations, complementary user-entity controls — maintained in place and exported for the report.
Sub-service organisations
Tracked in the vendor register with the carve-out or inclusive method noted, and their own SOC reports held as evidence.
Compliance Journey
A six-phase view of where the programme is — scoping to report — so the board sees a stage and a date, not a percentage.
HIPAA and privacy alignment
For healthcare-adjacent services, the Privacy category and HIPAA safeguards are evidenced from the same records.
How it shows up in a tenant
SOC 2 is enabled per tenant; these are the screens it adds.
SOC 2 dashboard
Posture across the 61-control catalogue, by criteria category.
Evidence
Dated against each control, with an AI review step and a human decision on every upload.
Foundation documents
System Description and Management Assertion, maintained in place and exported for the report.
Reports
Readiness report before engagement; control matrix and evidence index for the audit.
Frameworks in this discipline
SOC 2 Trust Services Criteria
Map the Trust Services Criteria, maintain your system description, and evidence control operation across the observation period.
Open the framework page →ISO/IEC 27001:2022 Information Security Management
Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.
Open the framework page →ISO/IEC 20000-1:2018 IT Service Management
Evidence your service management system against every ISO/IEC 20000-1:2018 requirement, from planning to continual improvement.
Open the framework page →Health Insurance Portability and Accountability Act
Run the required risk analysis, evidence administrative, physical and technical safeguards, and manage business associate obligations.
Open the framework page →SOC 2 Assurance
Does GRCLens issue the SOC 2 report?
No. SOC 2 reports are issued by a licensed CPA firm. GRCLens prepares the programme — scoping, controls, evidence over the observation period — and gives the auditor a workspace to sample from.
We already hold ISO/IEC 27001. How much of SOC 2 is covered?
A large share of the Security common criteria maps to ISO/IEC 27001 Annex A controls and the evidence already collected for them. The platform shows the mapping and the remaining gaps rather than a percentage, because auditors sample controls, not percentages.
Can we start with Type 1 and move to Type 2?
Yes. The same control set and evidence workflow serve both; Type 2 adds the observation period, during which dated evidence accrues against every control — worth starting from day one so the period is already running.
Deep expertise across the disciplines that matter

Walk into the audit with a population, not a promise
A walkthrough of the SOC 2 dashboard, the evidence calendar and the auditor workspace, mapped to any standard you already hold.