Controls

The 21 SOC 2 controls explained

ReadySOC pre-loads 21 controls across the 5 SOC 2 Trust Service Criteria. Here's what each one means in plain English.

Common Criteria (CC) — Required for all

  • CC1.1 — Your leadership demonstrates a genuine commitment to ethics and doing the right thing.
  • CC1.2 — There's appropriate oversight of your security program (e.g., a board, advisory committee, or designated security owner).
  • CC2.1 — Security policies and responsibilities are communicated clearly to your team.
  • CC3.1 — You have clear business objectives that help you identify security risks.
  • CC3.2 — You have a process to identify and assess risks to your systems and data.
  • CC6.1 — You control who can access your systems — only the right people get in.
  • CC6.2 — When you add a new employee or contractor, you have a process for granting them appropriate access.
  • CC6.3 — When someone leaves, you promptly remove their access to all systems.
  • CC7.1 — You monitor your systems for unusual activity, vulnerabilities, and threats.
  • CC7.2 — When a security incident occurs, you have a plan to respond, contain, and recover.

Availability (A) — If you have uptime commitments

  • A1.1 — Your availability commitments to customers are documented and achievable.
  • A1.2 — You monitor your systems to ensure you can meet those commitments.
  • A1.3 — You have a disaster recovery plan to restore service if something goes wrong.

Confidentiality (C) — If you handle sensitive data

  • C1.1 — You know what confidential information you hold and protect it appropriately.
  • C1.2 — When confidential data is no longer needed, you dispose of it securely.

Processing Integrity (PI) — For data processing companies

  • PI1.1 — Your data processing is complete, accurate, and timely.
  • PI1.2 — Data coming into your system is validated for accuracy and completeness.
  • PI1.3 — Data going out of your system is accurate and delivered as expected.

Privacy (P) — If you collect personal information

  • P1.0 — You have a privacy notice that explains how you collect and use personal data.
  • P3.1 — You only collect personal information you have a legitimate basis for collecting.
  • P4.1 — You collect only the minimum personal data necessary for your purposes.

Tip: Click on any control in ReadySOC and use the AI guidance button to get specific evidence requirements and implementation steps for that control.