Skip to content

SOC 2

SOC 2 with an evidence trail, not screenshot diaries.

Map Trust Services Criteria to controls and owners, maintain evidence for the relevant period and reuse genuine overlap with ISO 27001 in the same data model.

Trust Services Criteria covered (Security mandatory, A/PI/C/P optional)
5
Type I point-in-time and Type II over observation period
2 report types
Shared controls feed SOC 2 and ISO 27001 from one workspace
1 library

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • SOC 2Requirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

Evidence tied to the relevant period

SOC 2 Type II considers control effectiveness over a period. KaitoSec connects relevant signals from cloud, identity and developer systems to the corresponding control; your team reviews and approves the evidence.

02

Type I and Type II readiness

A Type I report confirms your controls are suitably designed at a point in time. A Type II report covers operating effectiveness over an observation period. KaitoSec supports both, with a clear pathway from your first Type I to ongoing Type II readiness.

03

Customer Trust Center

Provide approved SOC 2 reports, security policies and subprocessors under controlled access. Sales and security then work from the same reviewed state.

The workflow

01

Map controls to the Trust Services Criteria

Map your existing controls to all five Trust Services Criteria: Security (CC), Availability (A), Processing Integrity (PI), Confidentiality (C) and Privacy (P). KaitoSec shows which criteria your auditor is examining and what evidence is required for each.

02

Cloud systems as reviewable evidence sources

Connect AWS, GCP, Azure, GitHub and Okta as potential evidence sources. Access reviews, encryption status and vulnerability scans are assigned to the corresponding control for professional review.

03

Work with your auditor in one workspace

Invite your CPA firm to a dedicated workspace where they can review evidence, raise requests, and mark controls as tested. Audit fieldwork happens inside KaitoSec, no email chains, no shared drives, no confusion about which evidence version is current.

FAQ

What is the difference between SOC 2 Type I and Type II?

A SOC 2 Type I report assesses whether your controls are suitably designed at a specific point in time. A SOC 2 Type II report tests whether those controls operated effectively over an observation period, typically 6 to 12 months. Enterprise customers almost always require Type II because it demonstrates sustained operational effectiveness, not just good intentions.

Which Trust Services Criteria do we need to include?

Security (the Common Criteria) is mandatory in every SOC 2 engagement. The remaining four, Availability, Processing Integrity, Confidentiality and Privacy, are optional and selected based on what matters to your customers. Most SaaS companies include Security and Availability as a minimum.

How long does it take to get a SOC 2 report?

Duration depends on scope, maturity, implementation gaps, observation period and the CPA firm. KaitoSec structures controls and period-specific evidence; agree a defensible timeline with the auditor.

Do we need to hire a specialist to prepare for SOC 2?

KaitoSec provides enough built-in guidance that many engineering-led teams complete SOC 2 preparation independently. The actual audit must be performed by an independent CPA firm. KaitoSec does not replace the auditor but takes away much of the manual work that makes audits expensive.

Can SOC 2 evidence be reused for ISO 27001?

Yes. SOC 2 Trust Services Criteria and ISO 27001 Annex A controls overlap significantly. KaitoSec maintains a cross-mapping and reuses evidence across both frameworks wherever possible. Organisations frequently pursue SOC 2 first for their US customer base and ISO 27001 for European enterprise sales, using the same underlying control library. This is exactly the cross-mapping argument behind resilience made easy: implement once, evidence it wherever it applies.

Related frameworks