Controls
The 21 SOC 2 controls explained
Last updated July 2026 · 5 min read
ReadySOC pre-loads 21 controls across the 5 SOC 2 Trust Service Criteria. Here's what each one means in plain English.
Common Criteria (CC) — Required for all
- CC1.1 — Your leadership demonstrates a genuine commitment to ethics and doing the right thing.
- CC1.2 — There's appropriate oversight of your security program (e.g., a board, advisory committee, or designated security owner).
- CC2.1 — Security policies and responsibilities are communicated clearly to your team.
- CC3.1 — You have clear business objectives that help you identify security risks.
- CC3.2 — You have a process to identify and assess risks to your systems and data.
- CC6.1 — You control who can access your systems — only the right people get in.
- CC6.2 — When you add a new employee or contractor, you have a process for granting them appropriate access.
- CC6.3 — When someone leaves, you promptly remove their access to all systems.
- CC7.1 — You monitor your systems for unusual activity, vulnerabilities, and threats.
- CC7.2 — When a security incident occurs, you have a plan to respond, contain, and recover.
Availability (A) — If you have uptime commitments
- A1.1 — Your availability commitments to customers are documented and achievable.
- A1.2 — You monitor your systems to ensure you can meet those commitments.
- A1.3 — You have a disaster recovery plan to restore service if something goes wrong.
Confidentiality (C) — If you handle sensitive data
- C1.1 — You know what confidential information you hold and protect it appropriately.
- C1.2 — When confidential data is no longer needed, you dispose of it securely.
Processing Integrity (PI) — For data processing companies
- PI1.1 — Your data processing is complete, accurate, and timely.
- PI1.2 — Data coming into your system is validated for accuracy and completeness.
- PI1.3 — Data going out of your system is accurate and delivered as expected.
Privacy (P) — If you collect personal information
- P1.0 — You have a privacy notice that explains how you collect and use personal data.
- P3.1 — You only collect personal information you have a legitimate basis for collecting.
- P4.1 — You collect only the minimum personal data necessary for your purposes.
Tip: Click on any control in ReadySOC and use the AI guidance button to get specific evidence requirements and implementation steps for that control.