AICPA · International

SOC 2 Trust Services Criteria compliance software

Map the Trust Services Criteria, maintain your system description, and evidence control operation across the observation period.

Overview

What SOC 2 requires

SOC 2 is an attestation report produced by an independent CPA firm against the AICPA's Trust Services Criteria. Unlike a certification, there is no pass mark — the auditor issues an opinion on whether controls are suitably designed and, for a Type II report, whether they operated effectively over a defined period.

The criteria cover Security (the common criteria, always in scope) plus Availability, Processing Integrity, Confidentiality and Privacy, which are included at the organisation's discretion based on customer commitments.

The demanding part of a Type II is duration. Controls must be shown to have operated consistently across the entire observation window, typically three to twelve months. Evidence gathered retrospectively at the end of the period is exactly what auditors flag as an exception.

Who it applies to

  • SaaS and technology providers asked for SOC 2 by enterprise customers
  • Service organisations handling customer data on their clients' behalf
  • Organisations moving from a Type I to a Type II report
  • Vendors responding to security questionnaires that require attestation

At a glance

  • Issuing body: AICPA
  • Report types: Type I (point in time), Type II (period of operation)
  • Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy
  • Outcome: Independent auditor's opinion, not a certification
In the platform

How GRCLens supports SOC 2

SOC 2 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Trust Services Criteria mapping

The common criteria and optional categories are pre-loaded and mapped to your controls.

System description

Draft and maintain the system description that accompanies the report, kept in step with your control set.

Continuous evidence capture

Collect evidence as controls operate through the observation period rather than reconstructing it before the audit.

Management assertion support

Assemble the assertion and supporting control matrix your auditor will request.

Questions

SOC 2 frequently asked questions

What is the difference between SOC 2 Type I and Type II?

A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report additionally assesses whether those controls operated effectively across a defined period, usually three to twelve months.

Does GRCLens replace the auditor?

No. A SOC 2 report can only be issued by an independent CPA firm. GRCLens prepares the control environment, system description and evidence the auditor will examine.

Which Trust Services Criteria should we include?

Security is always in scope. The other four categories are selected based on the commitments you make to customers. Including categories you have not committed to adds audit cost without commercial benefit.

Talk to us about SOC 2

Security Solution Consultants provides SOC 2 readiness and audit preparation alongside the platform, so you can combine tooling with hands-on expertise.

Contact us