Getting Started with SOC 2
SOC 2 (System and Organization Controls 2) is the security framework US enterprise customers expect from SaaS vendors. A SOC 2 report — issued by a licensed CPA firm — attests that your organization’s controls around security, availability, processing integrity, confidentiality, and privacy meet AICPA Trust Services Criteria. Matproof maps the SOC 2 Common Criteria (CC) and selected additional criteria to your controls, evidence, and policies so you can prepare for audit without a spreadsheet.Activate SOC 2 under Settings → Frameworks → SOC 2. Your control set (~60 controls mapped to the 33 Common Criteria) will be pre-populated. You can add criteria for Availability, Confidentiality, and Privacy separately.
SOC 2 Type I vs. Type II
The 5 Trust Services Criteria
Most SaaS companies start with Security only. Add Availability and Confidentiality for enterprise deals.
Recommended Implementation Plan
Evidence Checklist
These are the most commonly requested evidence items in a SOC 2 audit:Common Audit Findings
1. No formal offboarding process
The most frequent CC6 finding. “We remove access when people leave” is not sufficient — auditors want a ticket or checklist showing the exact steps taken for each departure.2. Access reviews not completed on schedule
Committing to quarterly reviews in your policy and then having no evidence of review completion in the audit period is an immediate finding.3. Subservice organization SOC 2 reports not reviewed
SOC 2 best practice requires you to obtain and review your key subservice organizations’ SOC 2 reports regularly (typically annually). Stripe, AWS, and your identity provider all publish these. Document that you have reviewed them.Next Steps
- Evidence Collection — connecting integrations and automating evidence uploads
- People Module — employee records, access reviews, and offboarding checklists
- Vendor Risk — managing subservice organizations and requesting their SOC 2 reports
- Audit Programs — running your SOC 2 readiness assessment