NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new

SOC 2: scope, Type 1 vs Type 2, readiness and tools

SOC 2 is buyer-driven, so the programme starts with the deal rather than the framework: which customer is asking, and what would they accept instead. Two decisions then set the shape of everything that follows. Scope first: Security is mandatory, and every optional criterion you add is another set of controls to operate and evidence for the whole window. Report type second, because a Type 2 needs an observation period and that fixes the calendar. The AICPA publishes criteria rather than controls, so readiness is scored against a control set mapped to them, whether you build that set yourself or start from a platform library. Only then does software choice matter, judged on whether it carries evidence across the period.

5 pages on SOC 2, in the order the work happens. Jump to the stage you are at, or read straight through.

Score your readiness

Map your controls and evidence against the criteria you put in scope and give each open item an owner before the observation window opens.

Also relevant

These sit under another subject but bear directly on SOC 2.

Stop reading. Start scoring.

The free compliance check runs the SOC 2 gap assessment in about five minutes and gives you a scored report you can take to a board meeting.

14-day free trial · no credit card · unlimited users