SOC 2 Guide

This series examines the common criteria used to evaluate the Security category in a SOC 2 Type 2 examination. A Type 2 examination assesses the suitability of control design and operating effectiveness over a specified period. Each article will explain an individual criterion through practical examples of controls and supporting evidence for organizations with 5, 100, and 1,000 people. The examples will illustrate how organizations can address the same objective through approaches appropriate to their risks, structure, and resources. Links will be added below as articles are published.

CC1

CC2

  • CC2.1: Coming soon
  • CC2.2: Coming soon
  • CC2.3: Coming soon

CC3

  • CC3.1: Coming soon
  • CC3.2: Coming soon
  • CC3.3: Coming soon
  • CC3.4: Coming soon

CC4

  • CC4.1: Coming soon
  • CC4.2: Coming soon

CC5

  • CC5.1: Coming soon
  • CC5.2: Coming soon
  • CC5.3: Coming soon

CC6

  • CC6.1: Coming soon
  • CC6.2: Coming soon
  • CC6.3: Coming soon
  • CC6.4: Coming soon
  • CC6.5: Coming soon
  • CC6.6: Coming soon
  • CC6.7: Coming soon
  • CC6.8: Coming soon

CC7

  • CC7.1: Coming soon
  • CC7.2: Coming soon
  • CC7.3: Coming soon
  • CC7.4: Coming soon
  • CC7.5: Coming soon

CC8

  • CC8.1: Coming soon

CC9

  • CC9.1: Coming soon
  • CC9.2: Coming soon

Need help getting ready for SOC 2?