SOC 2 Criteria Directory
Browse all 33 mandatory Security controls, translated from AICPA legalese into plain English with exact evidence requirements.
Control Environment
Tone at the top, ethical values, and board oversight.
Communication & Information
Internal and external communications regarding security.
Risk Assessment
Identifying and analyzing risks to the achievement of objectives.
Monitoring Activities
Ongoing evaluations of internal control performance.
Control Activities
Policies and procedures that mitigate risks.
Logical Access Controls
Authentication, authorization, and securing physical/logical access.
System Operations
Monitoring system performance, anomalies, and incident response.
Change Management
Authorizing, testing, and deploying system changes securely.
Risk Mitigation
Business continuity, vendor management, and risk treatment.
Track all 33 controls for free
SOC2Checklist gives you the complete framework mapped, assigned, and tracked. No sales call. No credit card.
Start Free Today