Other frameworks
SOC 2: AICPA Trust Services Criteria
SOC 2 is the American Institute of CPAs' Trust Services Criteria framework, used by an independent service auditor to examine a service organisation's controls in a Type I (design, at a point in time) or Type II (design and operating effectiveness, over a period) report. EuroCompliant tracks the full 33-point Common Criteria (CC1-CC9), required in every SOC 2 examination, plus the Availability (A1), Confidentiality (C1) and Processing Integrity (PI1) supplemental categories, 43 obligations in total. It's a US standard rather than EU legislation, and it's paywalled: the platform's content is written from general knowledge and cross-checked against multiple independent secondary sources, not a purchased copy of the AICPA document, so treat every summary as a paraphrase rather than verbatim TSC wording.
Transcript
SOC 2 is the AICPA's Trust Services Criteria, the standard US enterprise buyers ask for during vendor due diligence.
Enabling it adds forty three obligations to your list: the full Common Criteria, plus availability, confidentiality, and processing integrity.
The SOC 2 Readiness Report is a live scorecard, computed from the exact same obligation tracker you see on the Obligations page, so it can never drift out of sync with it.
Twelve of those forty three obligations are platform managed today, driven by real evidence: policy acknowledgment, identity and endpoint audits, cloud configuration and vulnerability scans, audit trail activity, and recovery planning.
The rest are honest tenant actions: control activities, change management, business continuity, the things only your own team can actually attest to.
A high readiness score is not a SOC 2 report. That still takes an independent service auditor. This just gets you organised before you talk to one.
Why this is required
The Common Criteria (CC1-CC9) are mandatory for every SOC 2 report regardless of which supplemental categories are in scope: control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation.
Availability (A1.1-A1.3) covers capacity management, backup and recovery infrastructure, and periodic recovery-plan testing, for organisations whose SOC 2 scope includes uptime commitments.
Confidentiality (C1.1-C1.2) covers identifying and classifying confidential information and its secure disposal, for organisations with contractual or regulatory confidentiality commitments beyond personal data.
Processing Integrity (PI1.1-PI1.5) covers input, processing, output and storage completeness/accuracy, for organisations whose service commits to correct processing outcomes, not just data protection.
What EuroCompliant does
Enabling SOC 2 adds 43 obligations to your Obligations page. 12 are platform-managed, evidenced by real, continuous checks: CC1.2/CC2.1/CC2.2 (staff acknowledgment of current policies), CC6.1/CC6.2/CC6.3 (identity audit: MFA enforcement, dormant/orphaned accounts), CC6.6 (endpoint device compliance: disk encryption, patching, passcode policy), CC6.7 (CSPM scan of cloud infrastructure configuration), CC7.1 (dependency and container vulnerability scanning), CC7.2 (audit-trail activity), CC9.2 (vendor risk assessments), and A1.2 (recovery infrastructure planning, evidenced by RTO/RPO defined on your critical systems). Each of these is an honest, narrow proxy for its criterion, not full coverage — for example CC6.6's endpoint-compliance check evidences device hygiene, not general network perimeter controls, and the guidance on the Obligations page says so explicitly.
The remaining 32 obligations, covering the rest of the Common Criteria and all of Availability/Confidentiality/Processing Integrity, are tenant actions with specific, criterion-grounded guidance rather than generic placeholders.
Two document types are available from the Documents section: a SOC 2 System Description (your registered systems and monitored infrastructure connectors, structured as the narrative component of a Type I/II report) and a SOC 2 Readiness Report (a live pre-audit scorecard computed from the same obligation tracker this page shows, so it can't drift out of sync with what you see here). Neither substitutes for an independent service auditor's actual examination.
Walking through it
Enable SOC 2
Adds all 43 obligations, including the 12 platform-managed checks.
Open /settings/profile?tab=frameworks →Work the platform-managed criteria
Connect an identity source (Google Workspace, GitHub org, or Microsoft 365), an MDM connector, and a cloud/vulnerability scanner to drive CC6.1-CC6.3, CC6.6-CC6.7 and CC7.1 automatically; require staff acknowledgment on your current policies to drive CC1.2/CC2.1/CC2.2; keep the platform's audit trail active to drive CC7.2; and define RTO/RPO on your critical systems to drive A1.2.
Open /settings/integrations →Generate your System Description and Readiness Report
Review both before engaging an auditor. The Readiness Report shows exactly which criteria are complete, in progress, or need manual attestation and evidence.
Open /compliance-docs →The law
Control environment through control activities
Organisational integrity and ethics, communication of security policies, risk assessment, monitoring, and control activities -- the governance foundation every SOC 2 report requires.
Logical and physical access controls
Access provisioning/de-provisioning, least privilege, physical access restriction, boundary protection, data transmission protection, and malware prevention.
System operations
Vulnerability detection and monitoring, security event evaluation, incident response, and incident recovery.
Change management and risk mitigation
Controlled change management, business continuity planning, and vendor/business-partner risk assessment.
Availability, Confidentiality, Processing Integrity
Supplemental categories in scope only if the service organisation's own SOC 2 examination includes them.
Frequently asked
Do we need SOC 2 or ISO 27001?
They cover overlapping ground (access control, incident response, vulnerability management) but serve different audiences: SOC 2 is the standard US enterprise buyers ask for during vendor due diligence, while ISO 27001 is the internationally recognised certifiable standard. Many organisations selling into both markets end up doing both; this platform's obligation tracker and evidence checks are shared across the two where the underlying control is genuinely the same.
Is generating the Readiness Report the same as passing a SOC 2 audit?
No. It's a pre-audit self-assessment computed from your own tracked evidence and manual attestations. An actual SOC 2 report (Type I or Type II) requires an independent, licensed service auditor to examine your controls; this platform helps you get ready for that engagement and organise the evidence it will ask for.
Related guides
ISO 27001: information security management
The international standard for an information security management system, and how EuroCompliant tracks your Annex A controls.
Automated scanning & testing
Testing live systems for bias, robustness, prompt injection and data leakage: the evidence Articles 10 and 15 actually require.
Team, roles and access control
Inviting your team, assigning roles, organising departments, and locking down accounts with 2FA and SSO.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial