Attestation · Filed · London · 10 min read
The SOC 2 Controls List, Written for Engineers
A pragmatic walk-through of the Trust Services Criteria control families — access, change, vendor, incident, monitoring — with the evidence auditors actually test.
By Cyber Inspect Editorial Board
Nine Common Criteria, one operating model
Security's Common Criteria (CC1 – CC9) organize every SOC 2 control. Read them as an operating model, not a checklist, and evidence collection stops being a monthly fire drill.
The nine families in plain language
- CC1 — Control environment: governance, ethics, and org structure.
- CC2 — Communication and information: how information flows to the people who need it.
- CC3 — Risk assessment: annual risk register with treatment plan.
- CC4 — Monitoring: how you know the controls are still operating.
- CC5 — Control activities: the design of your controls.
- CC6 — Logical and physical access: identity, authentication, authorization.
- CC7 — System operations: change, availability, incident response.
- CC8 — Change management: the software delivery lifecycle.
- CC9 — Risk mitigation: vendor risk and business continuity.
Where auditors focus
Access reviews (CC6), change management (CC8), and vendor risk (CC9) draw the most exceptions in first-time audits. Instrument these first.