Service Organization Control 2
Trust service criteria framework for evaluating controls related to security, availability, processing integrity, confidentiality, and privacy. Required by enterprise customers for vendor assessment.
What SOC 2 draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Logical Access Security
Entity MUST implement logical access security software, infrastructure, and architectures to protect against threats.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
System Monitoring
Entity MUST monitor system components for anomalies indicative of malicious acts or system failures.
Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.
Security Event Evaluation
Entity MUST evaluate security events to determine whether they could impact ability to meet objectives.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Change Management
Entity MUST authorize, design, develop, configure, test, approve, and implement changes to meet objectives.
Change control fails at the evidence step far more often than at the approval step. Running SELECT 'CR:12345' WHERE 1 = 0 before a change ties every subsequent statement in that session to the request that authorised it — no agents, no application changes, no database configuration. Schema and configuration changes are captured as they happen, so an unapproved DDL is visible rather than discovered at the next review.
What SOC 2 covers
This instrument defines no data category of its own. Scope is whatever the service organisation defines in its system description and the criteria it selects. There is no fixed data class — which is why two SOC 2 reports can cover very different things.
How SOC 2 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by No regulator. Your customers, through the contract and the renewal.
A voluntary standard. No regulator enforces it.
SOC 2 is an attestation performed by an independent CPA firm against criteria you select. Nobody can sanction you for failing it. What happens instead is that the report carries exceptions, procurement asks about them, and the contract that required a clean report does not renew.
Where a customer contract warrants that you hold a clean SOC 2, failing it becomes a breach of that contract — which is a real exposure, just not a regulatory one.
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for SOC 2,
not configured for it afterwards
Trust Services Monitoring
Policies aligned to all five trust service criteria
SOC 2 Control Evidence
Auditor-ready evidence for Type I and Type II reports
Security Event Dashboard
Real-time visibility into CC7.2 and CC7.3 events
Anomaly Detection
AI-powered detection of unusual system behavior
Other Security frameworks
Walk into the SOC 2 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.