HomeDomainsSOC 2 Assurance
Discipline 04

SOC 2 Assurance

Trust Services Criteria readiness for service organisations, end to end — from scoping the system description to the evidence an auditor will sample over the observation period.

At a glance
  • CriteriaSecurity + Availability, Processing Integrity, Confidentiality, Privacy
  • Report typesType 1 (point in time) · Type 2 (period)
  • IssuerAICPA — reports by a licensed CPA firm
  • ObservationTypically 6–12 months for Type 2
Discipline 04
Why it matters

SOC 2 Assurance

SOC 2 is how a service organisation proves to its customers that the controls protecting their data actually operate. A Type 1 report describes the controls at a point in time; a Type 2 report has an auditor test them over an observation period — which is where most programmes discover that a control which exists on paper was not operating every week.

The work is evidence, on a calendar. Access reviews, change approvals, backup tests, vendor reviews and incident records have to happen on schedule and leave a record the auditor can sample. Teams that treat SOC 2 as a document exercise arrive at the audit with policies and no population.

GRCLens runs SOC 2 as a continuous programme: the Trust Services Criteria are mapped to the common control model, recurring evidence is scheduled and collected as it happens, and every control shows its coverage of the observation period before the auditor asks.

Discipline 04

What the platform does for SOC 2

01

Criteria mapped, not copied

The Common Criteria and the optional categories map to controls already evidenced for ISO/IEC 27001 and ISO/IEC 20000, so a service organisation with either standard starts well above zero.

02

Evidence, dated, per control

Access reviews, change tickets and restore tests are attached to the control with their date, so what was collected during the observation period — and what was not — is visible before the auditor asks.

03

System Description and Management Assertion

Both held as documents in the SOC 2 foundation module — scope, boundaries, sub-service organisations, complementary user-entity controls — maintained in place and exported for the report.

04

Sub-service organisations

Tracked in the vendor register with the carve-out or inclusive method noted, and their own SOC reports held as evidence.

05

Compliance Journey

A six-phase view of where the programme is — scoping to report — so the board sees a stage and a date, not a percentage.

06

HIPAA and privacy alignment

For healthcare-adjacent services, the Privacy category and HIPAA safeguards are evidenced from the same records.

In the platform

How it shows up in a tenant

SOC 2 is enabled per tenant; these are the screens it adds.

01

SOC 2 dashboard

Posture across the 61-control catalogue, by criteria category.

02

Evidence

Dated against each control, with an AI review step and a human decision on every upload.

03

Foundation documents

System Description and Management Assertion, maintained in place and exported for the report.

04

Reports

Readiness report before engagement; control matrix and evidence index for the audit.

Questions

SOC 2 Assurance

Does GRCLens issue the SOC 2 report?

No. SOC 2 reports are issued by a licensed CPA firm. GRCLens prepares the programme — scoping, controls, evidence over the observation period — and gives the auditor a workspace to sample from.

We already hold ISO/IEC 27001. How much of SOC 2 is covered?

A large share of the Security common criteria maps to ISO/IEC 27001 Annex A controls and the evidence already collected for them. The platform shows the mapping and the remaining gaps rather than a percentage, because auditors sample controls, not percentages.

Can we start with Type 1 and move to Type 2?

Yes. The same control set and evidence workflow serve both; Type 2 adds the observation period, during which dated evidence accrues against every control — worth starting from day one so the period is already running.

Walk into the audit with a population, not a promise

A walkthrough of the SOC 2 dashboard, the evidence calendar and the auditor workspace, mapped to any standard you already hold.