Loading Vaultize
Skip to main content

Compliance/Security frameworks/SOC 2

Sixty-one criteria: fifteen leave evidence in the file.

SOC 2 is an auditor’s opinion on your controls. Vaultize adds records that stay with the data, ready for the evidence request.

SECAVAPICONPRI
SECSecurity9 outcomes
Read againstAICPA Trust Services Criteria, TSP Section 100 (2017, revised points of focus 2022)AICPA TSC 2017 · Points of focus revised 2022
  • Attestation report, not certification
  • Capability mapping, not an opinion
  • AICPA TSC 2017 · Points of focus 2022
15of 61 Trust Services Criteria

The answer in 30 seconds

Vaultize adds file-level records to 15 criteria across Security, Availability, Confidentiality and Privacy. Processing Integrity and the other 46 belong to other control owners.

The criteria in one view

Five categories. Sixty-one criteria. Where file evidence lands.

Security is required in every SOC 2 report. The other four categories are included when the service commits to them. Select a category to see which criteria a governed file can evidence.

SECSECURITYAVAAVAILABILITYPIPROCESSINGINTEGRITYCONCONFIDENTIALITYPRIPRIVACY

SEC

Security

Common criteria CC1 to CC9. Required in every report.

Outcomes the file can evidence

How Vaultize contributes
Vaultize Seal binds access rights and encryption to the file and revokes them in real time. Vaultize Share governs transfer through MFA-enabled links. Per-access telemetry feeds monitoring and incident evaluation. Vaultize Secure gives recovery a separate path.
Evidence to retain
Sealed rights and revocations. Transfer and recipient records. Access telemetry. Recovery events.

Criterion by criterion

What each criterion asks. What the file can answer.

Criterion identifiers and series names are from the AICPA Trust Services Criteria. Each description is a one-line paraphrase; read the criterion and its points of focus in the AICPA document. Each row is a capability mapping, not an auditor’s opinion.

Using this page

Where these rows fit in a SOC 2 examination.

A SOC 2 report is issued by a service auditor after examining your controls. This page is evidence for the criteria you map to.

  1. 1

    Scope the system

    Define the system and the categories the report will cover.

  2. 2

    Map the controls

    State which controls meet each criterion.

  3. 3

    Operate and collect

    Run the controls and keep the evidence. These rows belong here.

    Bring the fifteen rows above as evidence for the criteria you map.

  4. 4

    Auditor tests

    Type 1 tests design at a point in time. Type 2 tests operation over a period.

  5. 5

    Report issued

    The auditor’s opinion goes to user entities and their auditors.

Responsibility boundary

Controls support the opinion. A product does not give it.

Vaultize contributes technical controls and evidence to a SOC 2 examination. It does not perform the examination, form the opinion, or decide which criteria apply. The opinion belongs to the service auditor. Read the criteria and obtain qualified advice before relying on this page.

A practical next step

Bring your control matrix.

We will mark which criteria the governed file can evidence today. We will name the control owner responsible for the rest.

Request a compliance mapping session