SOC 2 readiness workspace | Compliancify

Organize system-description, criteria, risk, control, evidence, and management-responsibility records without representing readiness work as a completed CPA examination.

Public scope

Structured context for people and machine readers.

This is a public product and knowledge surface. Illustrative workflows do not establish a professional conclusion, legal or tax advice, guaranteed outcome, or live customer implementation.

  • System description & boundary
  • Risk assessment
  • Logical access
  • Change management
  • Availability & incident response
  • Vendor & subservice dependencies

Public knowledge 01

Source and applicability boundary

  1. 01

    AICPA SOC resource starting point

  2. 02

    Authoritative guides and criteria may require licensed access

  3. 03

    Independent CPA examination remains outside the product preview

  4. 04

    SOC 2 is an examination context for controls relevant to the Trust Services Criteria. The applicable criteria, system boundary, period, evidence, and examination conclusion require management and qualified CPA judgment.

  5. 05

    Official starting point: https://www.aicpa-cima.com/soc

Public knowledge 02

Obligation and control themes

  1. 01

    System description & boundary — Maintain approved system scope, services, commitments, components, boundaries, and material changes.

  2. 02

    Risk assessment — Operate a repeatable process to identify objectives, risks, changes, dependencies, and response decisions.

  3. 03

    Logical access — Govern provisioning, authentication, privileged access, recertification, removal, and monitored exceptions.

  4. 04

    Change management — Separate request, testing, approval, deployment, emergency handling, and post-implementation review.

  5. 05

    Availability & incident response — Coordinate monitoring, incident classification, escalation, communication, recovery, learning, and resilience commitments.

  6. 06

    Vendor & subservice dependencies — Identify dependency scope, due diligence, contractual expectations, monitoring, exceptions, and exit actions.

Public knowledge 03

Evidence and review expectations

  1. 01

    System description & boundary: System description, architecture, service commitments, inventory, data flows, vendors, and change record. Owner: System owner. Reviewer: Readiness reviewer. State: Interpretation pending.

  2. 02

    Risk assessment: Risk methodology, risk register, assessment records, approvals, and change triggers. Owner: Risk owner. Reviewer: Control reviewer. State: Mapped.

  3. 03

    Logical access: Identity configuration, access requests, approvals, reviews, logs, terminations, and exception records. Owner: Identity owner. Reviewer: Security reviewer. State: Evidence requested.

  4. 04

    Change management: Tickets, code review, test results, approvals, deployment logs, emergency records, and follow-up. Owner: Engineering owner. Reviewer: Change reviewer. State: Reviewer decision.

  5. 05

    Availability & incident response: Alerts, incident records, communications, recovery tests, post-incident review, and action tracking. Owner: Incident owner. Reviewer: Resilience reviewer. State: Mapped.

  6. 06

    Vendor & subservice dependencies: Vendor inventory, due diligence, contracts, monitoring, incidents, exceptions, and exit plans. Owner: Vendor owner. Reviewer: Third-party risk reviewer. State: Reassessment due.

Public knowledge 04

Relationships without false equivalence

  1. 01

    ISO/IEC 27001 management-system controls

  2. 02

    NIST CSF 2.0 outcomes

  3. 03

    GDPR security and processor obligations