SOC 2 (AICPA Trust Services Criteria)
SOC 2 is an attestation against the AICPA Trust Services Criteria. What the catalog gives a service auditor is a witnessed activity log with an independent timestamp for the criteria the gateway touches (CC4, CC6, CC7, CC8, PI1, C1) — not screenshots, and not an opinion.
| Registry id | soc2 |
| Kind | attestation |
| Jurisdiction | US |
| Instrument | AICPA Trust Services Criteria 2017 (revised points of focus 2022) |
| Catalog versions | 2026-09 from 2018-12-15 (current) — TSC 2017, points of focus 2022 |
| Verified against instrument | yes |
| Tagging key (compliance tags) | soc2 |
| Incident deadline rules | none |
| Retention floors | *: 365 days |
| Obligations | 10 |
The retention floor *: 365 days is the default attestation (examination) period and applies to every system for which SOC 2 is active; declare a different period on the profile. SOC 2 has no reporting deadline, so incidents.reported_within_deadline is not_evaluable unless you declare an SLA.
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
Monitoring activities
Section titled “Monitoring activities”cc4-monitoring-activities · CC4.1, CC4.2 · applies from 2018-12-15
Ongoing and separate evaluations determine whether controls are present and functioning; deficiencies are communicated. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
Shows the monitoring ran; what a human did with its findings is shown in the inbox trail. |
| The tenant log’s tree heads covering the window were countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
Logical access security
Section titled “Logical access security”cc6-1-logical-access · CC6.1 · applies from 2018-12-15
Logical access security software, infrastructure and architectures protect information assets. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Grants, capability filters and argument policies are bound and sealed. | declared | authz.least_privilege_declared |
Whether the grants are the least the system needs is the operator’s judgement, not evaluated. |
| Approvals were decided by authenticated principals (2FA where policy requires it). | recomputed | authz.human_identity_verified |
Authentication is of the console account; who sat at the keyboard is not observable. |
System boundaries and transmission
Section titled “System boundaries and transmission”cc6-6-cc6-7-boundaries · CC6.6, CC6.7 · applies from 2018-12-15
Access from outside the system boundary is restricted and data movement is controlled — policy denials and residency blocks at the gateway. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every action outside the contract or grant was refused. | recomputed | authz.out_of_grant_refused |
Covers actions the gateway observed; the grant itself is a declaration. |
| Every data-movement refusal (residency block) produced a sealed record. | recomputed | access.sensitive_reads_recorded {"tag": "soc2.cc6.7"} |
Counts actions the tagging engine marked; untagged traffic is not in the denominator. |
Prevention of unauthorised or malicious software and change
Section titled “Prevention of unauthorised or malicious software and change”cc6-8-unauthorised-change · CC6.8 · applies from 2018-12-15
Controls prevent or detect the introduction of unauthorised software or configuration. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| No grant was widened without going through the lifecycle gate. | recomputed | change.no_unapproved_widening |
Covers configuration held by the gateway; upstream changes (a vendor’s model) are shown as drift. |
Monitoring for anomalies
Section titled “Monitoring for anomalies”cc7-2-anomaly-monitoring · CC7.2 · applies from 2018-12-15
System components are monitored for anomalies indicative of malicious acts or errors. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every guardrail block the tagging engine marked CC7.2 produced a sealed record. | recomputed | access.sensitive_reads_recorded {"tag": "soc2.cc7.2"} |
Counts actions the tagging engine marked; untagged traffic is not in the denominator. |
| Every governed action produced a sealed record, including refusals. | recomputed | records.every_verdict_sealed |
Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately. |
| The audit row chain over the window recomputes intact, or every gap is a declared prune. | recomputed | records.integrity_verified |
Detects alteration after the fact; it cannot show that a row was accurate when written. |
Security events and incident response
Section titled “Security events and incident response”cc7-3-cc7-4-incidents · CC7.3, CC7.4 · applies from 2018-12-15
Security events are evaluated; identified incidents are responded to under a defined programme. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
Shows incidents someone entered; an incident nobody recorded cannot be counted. |
| Incidents were reported within the customer-defined SLA. | recomputed | incidents.reported_within_deadline {"framework": "soc2"} |
SOC 2 sets no reporting deadline; without a declared SLA this statement cannot be evaluated. Deadlines are shown, not enforced. |
Change management
Section titled “Change management”cc8-1-change-management · CC8.1 · applies from 2018-12-15
Changes to infrastructure, data, software and procedures are authorised, tested and documented. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every contract promotion has a sealed epoch-boundary record naming its approver. | recomputed | change.promotions_sealed |
Changes made outside the contract lifecycle are not visible here. |
Processing integrity of outputs
Section titled “Processing integrity of outputs”pi1-4-pi1-5-processing-integrity · PI1.4, PI1.5 · applies from 2018-12-15
Outputs are complete, accurate and timely; stored items are protected from alteration. Applies to every system for which the framework is active.
What the gateway cannot show: The accuracy of a model’s output is not recomputable; alteration after the fact is.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The audit row chain over the window recomputes intact, or every gap is a declared prune. | recomputed | records.integrity_verified |
Detects alteration after the fact; it cannot show that a row was accurate when written. |
| Human approval requests were decided by humans (requested, decided, lapsed). | recomputed | oversight.exercised |
Records the fact of human disposition, not its quality. |
Confidential information
Section titled “Confidential information”c1-1-confidentiality · C1.1 · applies from 2018-12-15
Confidential information is identified and protected — records carry digests and an admitted-field allow-list, never bodies or identities. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The confidentiality commitments and the never-enters allow-list are declared. | declared | profile.field_declared {"path": "frameworks.soc2.confidentiality_reference"} |
The allow-list is a published design property; the customer’s own commitments are declared, not evaluated. |
Evidence retained for the attestation period
Section titled “Evidence retained for the attestation period”attestation-period-retention · SOC 2 Type II examination period · applies from 2018-12-15
The records an examination samples must exist for the whole period under review (default 365 days). Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Logs are kept for at least the attestation period (365 days by default). | recomputed | retention.floor {"floor_days": 365} |
The default period is 365 days; a different examination period is declared on the profile. Record identifiers, statements and tree heads are permanent. |
| Every gap in the retained logs is a declared prune. | recomputed | retention.declared_prunes |
A declared prune is shown as a gap with its reason; the pruned content cannot be recovered. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

