Free online trainings
24
Sep
Eramba Detailed Risk & Compliance Advanced
AICPA Trust Services Criteria - SOC 2

SOC 2 is a report about evidence over time

There is no SOC 2 certificate and no pass mark. A licensed CPA firm writes an opinion on whether your controls were designed well and, in a Type II, whether they actually ran for months. That is a record-keeping problem before it is a security one.

  • Any framework as a CSV
  • Unlimited users
  • Every module included
Trust Services CriteriaIn your report
  • SecurityThe common criteria, CC1 to CC9. Every SOC 2 report contains them.Always
  • AvailabilityUptime commitments, capacity, recovery.If selected
  • ConfidentialityInformation designated confidential, and how it is disposed of.If selected
  • Processing integrityProcessing that is complete, valid, accurate and timely.If selected
  • PrivacyPersonal information across notice, choice, retention and disclosure.If selected

Only Security is mandatory. Each category you add widens the report, the control set and the audit - so pick the ones your customers actually ask about.

Type I or Type II?

Both are the same criteria. They differ in what the auditor is allowed to say about them, and that difference is the whole reason a GRC tool matters here.

Type I - the design, on one day

An opinion that the controls were suitably designed as of a single date. Nothing is said about whether they ran.

  • What it asks for A description of the system and of each control, with an owner.
  • What it does not ask for A history. You can pass a Type I on your first day.

Type II - the operation, over a window

An opinion that the controls were designed well and operated effectively across a period, commonly three to twelve months. This is the one customers ask for.

  • What it asks for Evidence that each control ran on its stated schedule, for every period in the window, with the exceptions written down.
  • Where it goes wrong A control that is real but untracked. If nobody recorded the quarterly access review, the auditor treats it as not performed.

Between two reports a bridge letter covers the gap. It is your statement, not the auditor’s opinion.

The nine common criteria, and where they live

CC1 to CC5 follow the COSO framework - the governance half. CC6 to CC9 are the operational half. The first column is the criterion, the second is what eramba holds for it.

  • CC1Control environmentIntegrity and ethics, board oversight, structure and reporting lines, competence, accountability. Your organisational chart, your code of conduct, and evidence people read it.OrganisationPoliciesAwarenessCovered
  • CC2Communication and informationInternal and external communication of objectives and responsibilities. Policies published to the people they bind, with acknowledgements recorded per person.PoliciesAwarenessCovered
  • CC3Risk assessmentObjectives specified, risks identified and analysed, fraud considered, change assessed. A risk register with owners, a classification method of your own, and review dates.RiskCovered
  • CC4Monitoring activitiesOngoing and separate evaluations, and deficiencies communicated. Scheduled control testing, with a failed test raising a finding rather than passing quietly.Internal ControlsCovered
  • CC5Control activitiesControls selected to mitigate risk, technology controls included, deployed through policies and procedures. The link from a risk to the control that treats it.Internal ControlsPoliciesCovered
  • CC6Logical and physical accessIdentity, credentials, authorisation, removal on leaving, physical entry, disposal. eramba does not grant or revoke access - it holds the policy, the periodic account review, and the evidence that somebody did it.Internal ControlsOrganisationPartial
  • CC7System operationsDetecting anomalies, evaluating security events, incident response and recovery. The incident lifecycle with its timeline lives here; the monitoring that spots the event does not.ExceptionsInternal ControlsPartial
  • CC8Change managementAuthorising, designing, testing and approving changes to infrastructure, data and software. Your pipeline stays where it is; the approval record and the control that tests it are here.ProjectsInternal ControlsPartial
  • CC9Risk mitigationBusiness disruption and vendor risk. Send a vendor any questionnaire, score the answers, and carry the findings and contract dates that CC9.2 asks about.RiskOnline AssessmentsCovered
The record is erambaYou run it, eramba governs and evidences it

Under each criterion sit the points of focus. They are considerations the auditor weighs, not a checklist you must satisfy line by line - the AICPA says so explicitly, and treating them as requirements is the most common way a first SOC 2 doubles in size.

The mapping the report is built on

Section 3 of a SOC 2 report is your description of the system and its controls; section 4 is the auditor placing each criterion against the controls you claim satisfy it, and the tests they ran.

That mapping is a report in eramba, not a spreadsheet somebody maintains. Import the criteria as a CSV like any other framework, and each one carries its strategy, its owner, its linked policies and internal controls, and its status.

Trust Services CriteriaISO 27001:2022any CSV you upload
Compliance analysis showing each requirement with its strategy, internal controls and policies
Compliance Analysis: each requirement with its strategy, its linked controls and policies, and its status.

No tool can give you a SOC 2

The opinion is signed by a licensed CPA firm. Nobody else can issue it, and no software can shorten the window a Type II covers - if your customers want six months of evidence, that is six months.

What software decides is whether those six months exist as a record when the auditor asks. A control with an owner and a testing interval leaves a trail on its own; the same control kept in somebody’s calendar does not.

eramba is also not your auditor’s workpapers and not a monitoring agent. It will not watch your cloud accounts or collect a screenshot for you unless you point an automated test at the system that knows.

What you bring to the audit

The description

Your system, its boundaries and the controls you claim - written, approved and versioned.

The evidence

Each control tested on its schedule across the whole window, with results kept.

The exceptions

Where a control did not run, said plainly, with the corrective action attached.

The vendors

Subservice organisations, their own reports, and what you carved out.

Try it before you talk to anyone

The Community edition is free and self-hosted. Import the Trust Services Criteria as a CSV the same way every other framework is imported, and see what a year of evidence would look like before you sign with an audit firm.

Start the window before the auditor does

Flat annual price. Unlimited users, unlimited frameworks, every module included. Your bill does not grow with your team.

  • 39,030 downloads last year
  • 641 enterprise users
  • 11 releases last year
  • Used for ISO, PCI and SOC 2 since 2015

Pricing

Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.

Community

Free

Self-hosted. No user limit, no time limit.

Download

Enterprise on-premises

from 2500€/year

Runs on your infrastructure, with support and updates.

See pricing

Enterprise SaaS

from 5000€/year

Hosted and operated by eramba, in the EU.

See pricing

Contact us

A practitioner answers, not a sales sequence.