Attestation · Filed · London · 10 min read

The SOC 2 Controls List, Written for Engineers

A pragmatic walk-through of the Trust Services Criteria control families — access, change, vendor, incident, monitoring — with the evidence auditors actually test.

By Cyber Inspect Editorial Board

Nine Common Criteria, one operating model

Security's Common Criteria (CC1 – CC9) organize every SOC 2 control. Read them as an operating model, not a checklist, and evidence collection stops being a monthly fire drill.

The nine families in plain language

  • CC1 — Control environment: governance, ethics, and org structure.
  • CC2 — Communication and information: how information flows to the people who need it.
  • CC3 — Risk assessment: annual risk register with treatment plan.
  • CC4 — Monitoring: how you know the controls are still operating.
  • CC5 — Control activities: the design of your controls.
  • CC6 — Logical and physical access: identity, authentication, authorization.
  • CC7 — System operations: change, availability, incident response.
  • CC8 — Change management: the software delivery lifecycle.
  • CC9 — Risk mitigation: vendor risk and business continuity.

Where auditors focus

Access reviews (CC6), change management (CC8), and vendor risk (CC9) draw the most exceptions in first-time audits. Instrument these first.