Framework · SOC 2
SOC 2 is a continuous program, not a one-time audit
AICPA attestation framework across five Trust Services Criteria categories, reported as Type I or Type II. Continuous evidence, drift alerts, auditor access.
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA) and widely required by enterprise buyers in Canada and the United States, especially of SaaS and technology companies. It evaluates an organization's controls against the Trust Services Criteria, which cover Security, Availability, Processing Integrity, Confidentiality, and Privacy. The report is issued by a CPA firm.
Key facts
- 5 categories: Security (common criteria), Availability, Processing Integrity, Confidentiality, Privacy.
- Type I: attests to the design of controls at a point in time.
- Type II: attests to the operating effectiveness of controls over a defined period, typically six to twelve months.
- CPA: the report is issued by a licensed accounting firm after reviewing evidence covering the full period.
What SOC 2 requires
SOC 2 is not a one-time audit; it is a continuous compliance program. Auditors expect evidence covering the full audit period for Type II. A Type II report covers a fixed observation period, but the controls it attests to must operate continuously between audit cycles.
- CC1–CC3: governance, communication, control environment
- CC6: logical and physical access controls, MFA, privileged access management
- CC7: system operations management, anomaly detection
- CC8: change management; deployments, updates, patches
- CC9: risk management, vendor risk disclosure
- A1, C1, PI1, P1–P8: availability, confidentiality, processing integrity, privacy
What Sentrix provides for SOC 2
Automated evidence collection
Sentrix connects to AWS, Azure, GCP, Okta, GitHub and Jira, among others, via read-only OAuth integrations and collects evidence automatically: configuration snapshots, access logs, provisioning events, MFA enforcement status, pull request approvals and deployment records. No manual screenshots.
Mapping to the Trust Services Criteria
Sentrix maps each piece of evidence to the criteria it satisfies as it is ingested, surfacing gaps where controls are missing or where collected evidence does not yet satisfy a criterion. The control library is updated as the AICPA refines the criteria.
Type II readiness tracking
Sentrix tracks your coverage gaps throughout the observation period and alerts you before gaps become audit exceptions.
Monitoring between audit cycles
Sentrix alerts your team when a control drifts out of compliance: a firewall rule changes, MFA is disabled for a privileged account, a backup job fails to run. Alerts are routed through your existing incident management workflows.
CPA auditor workspace
A dedicated workspace for your CPA firm with read-only access to evidence organized by criterion, comment threads, and exception templates. No more sending ZIP files.
Trust center
Share your SOC 2 posture with customers and prospects via a real-time trust center instead of answering security questionnaires by hand.
Crosswalks
- ISO 27001: substantial overlap; SOC 2 evidence is mapped to Annex A controls.
- NIST CSF 2.0: the common criteria are mapped to the six CSF functions.
- HIPAA: HIPAA controls map to SOC 2 criteria for healthcare SaaS companies.
- PCI DSS: PCI DSS controls are mapped to SOC 2 for organizations holding both.
- OSFI B-10 / B-13: B-10 and B-13 control sets with crosswalks to SOC 2.
Further reading
SaaS and technology solution and healthcare solution.
See your SOC 2 readiness on your real infrastructure.
Frequently asked questions
- What is the difference between SOC 2 Type I and Type II?
- A Type I report attests to the design of your controls at a single point in time. A Type II report attests to the operating effectiveness of those controls over a defined observation period, typically six to twelve months, during which the auditor expects evidence covering the full period. Most enterprise buyers require a Type II report before signing.
- Do we need to maintain SOC 2 compliance after the report?
- Yes. A Type II report attests to controls operating over time, so the underlying controls need to keep running correctly between audit cycles. Sentrix monitors your environment continuously and alerts your team when a control drifts, for example when MFA is disabled for a privileged account, so issues get fixed and documented before they become audit findings.
- Can our SOC 2 evidence be reused for ISO 27001 or other frameworks?
- Yes. SOC 2 controls overlap significantly with ISO 27001 and NIST CSF. Sentrix maps your SOC 2 evidence to these adjacent frameworks automatically, so work done for one attestation contributes directly to the others instead of being duplicated. Each framework page lists the crosswalks delivered.
Related pages
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Framework · NIST CSF 2.0
NIST CSF 2.0: the risk framework your board understands
The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.
Framework · HIPAA
HIPAA continuous. Not HIPAA compliant once a year.
The Security Rule, Privacy Rule and Breach Notification Rule of the US HIPAA law, for covered entities and their business associates, monitored continuously.
Framework · PCI DSS v4.0.1
PCI DSS v4.0.1: 12 requirements, one evidence program
Payment Card Industry Data Security Standard: twelve requirements, quarterly vulnerability scans and annual validation by a QSA report or self-assessment.
Framework · OSFI B-10 / B-13
OSFI B-10 and B-13: outsourcing, technology and cyber risk
OSFI guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for Canada's federally regulated financial institutions, in one program.
Let's talk about your compliance program.
Last updated: 2026-09-17
