New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
← Legislation library

United States

SOC 2

SOC 2 is the AICPA's Trust Services Criteria framework used in service-organization audits. It covers the Common Criteria (security) and, where in scope, Availability, Confidentiality, and Processing Integrity, spanning control environment, access control, system operations, change management, and risk mitigation.

43 criterions

Criterion CC1.1

Commitment to integrity and ethical values

The entity demonstrates a commitment to integrity and ethical values.

Criterion CC1.2

Board independence and oversight

The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.

Criterion CC1.3

Organisational structure, authority, and responsibility

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.

Criterion CC1.4

Commitment to competence

The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

Criterion CC1.5

Accountability for internal control responsibilities

The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.

Criterion CC2.1

Quality information supporting internal control

The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

Criterion CC2.2

Internal communication

The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.

Criterion CC2.3

Communication with external parties

The entity communicates with external parties regarding matters affecting the functioning of internal control.

Criterion CC3.1

Objectives specified with clarity

The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.

Criterion CC3.2

Risk identification and analysis

The entity identifies risks to the achievement of its objectives across the entity and analyses risks as a basis for determining how the risks should be managed.

Criterion CC3.3

Fraud risk consideration

The entity considers the potential for fraud in assessing risks to the achievement of objectives.

Criterion CC3.4

Identifying and assessing changes

The entity identifies and assesses changes that could significantly impact the system of internal control.

Criterion CC4.1

Ongoing and separate evaluations

The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

Criterion CC4.2

Evaluating and communicating deficiencies

The entity evaluates and communicates internal control deficiencies in a timely manner to those responsible for taking corrective action.

Criterion CC5.1

Control activities mitigating risk

The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

Criterion CC5.2

General controls over technology

The entity also selects and develops general control activities over technology to support the achievement of objectives.

Criterion CC5.3

Deployment through policies and procedures

The entity deploys control activities through policies that establish what is expected and procedures that put policies into action.

Criterion CC6.1

Logical access security

The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.

Criterion CC6.2

User registration, authorisation, and de-provisioning

Prior to issuing system credentials and granting system access, the entity registers and authorises new internal and external users, and removes access when it is no longer required.

Criterion CC6.3

Role-based access and least privilege

The entity authorises, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, and the principle of least privilege.

Criterion CC6.4

Physical access restriction

The entity restricts physical access to facilities and protected information assets to authorised personnel.

Criterion CC6.5

Decommissioning protections

The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished, and is no longer required to meet objectives.

Criterion CC6.6

Boundary protection against external threats

The entity implements logical access security measures to protect against threats from sources outside its system boundaries.

Criterion CC6.7

Data transmission and movement controls

The entity restricts the transmission, movement, and removal of information to authorised internal and external users and processes, and protects it during transmission, movement, or removal.

Criterion CC6.8

Malicious software prevention and detection

The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software.

Criterion CC7.1

Vulnerability detection and monitoring

The entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.

Criterion CC7.2

Monitoring for security events

The entity monitors system components and the operation of controls to detect anomalies that are indicative of malicious acts, natural disasters, or errors affecting the entity's ability to meet its objectives.

Criterion CC7.3

Evaluating security events

The entity evaluates security events to determine whether they could or did result in a failure to meet objectives, and, if so, takes actions to prevent or address such failures.

Criterion CC7.4

Incident response

The entity responds to identified security incidents by executing a defined incident response programme to understand, contain, remediate, and communicate security incidents, as appropriate.

Criterion CC7.5

Recovery from security incidents

The entity identifies, develops, and implements activities to recover from identified security incidents.

Criterion CC8.1

Change authorisation and testing

The entity authorises, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.

Criterion CC9.1

Business disruption risk mitigation

The entity identifies, develops, and implements activities to mitigate risk arising from potential business disruptions.

Criterion CC9.2

Vendor and business partner risk management

The entity assesses and manages risks associated with vendors and business partners.

Criterion A1.1

Capacity management

The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.

Criterion A1.2

Environmental protections and backup infrastructure

The entity authorises, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.

Criterion A1.3

Recovery plan testing

The entity tests recovery plan procedures supporting system recovery to meet its objectives.

Criterion C1.1

Identifying and maintaining confidential information

The entity identifies and maintains confidential information to meet its objectives related to confidentiality.

Criterion C1.2

Disposal of confidential information

The entity disposes of confidential information to meet its objectives related to confidentiality.

Criterion PI1.1

Processing integrity objectives and system requirements

The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing integrity to support the use of the entity's products and services.

Criterion PI1.2

Input completeness, accuracy, and timeliness

The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives.

Criterion PI1.3

Processing completeness, accuracy, and timeliness

The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.

Criterion PI1.4

Output completeness, accuracy, and timeliness

The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives.

Criterion PI1.5

Storage completeness, accuracy, and timeliness

The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives.

Turn SOC 2 into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial