Compliance/Security frameworks/SOC 2
Sixty-one criteria: fifteen leave evidence in the file.
SOC 2 is an auditor’s opinion on your controls. Vaultize adds records that stay with the data, ready for the evidence request.
- Attestation report, not certification
- Capability mapping, not an opinion
- AICPA TSC 2017 · Points of focus 2022
The answer in 30 seconds
Vaultize adds file-level records to 15 criteria across Security, Availability, Confidentiality and Privacy. Processing Integrity and the other 46 belong to other control owners.
The criteria in one view
Five categories. Sixty-one criteria. Where file evidence lands.
Security is required in every SOC 2 report. The other four categories are included when the service commits to them. Select a category to see which criteria a governed file can evidence.
SEC
Security
Common criteria CC1 to CC9. Required in every report.
Outcomes the file can evidence
- How Vaultize contributes
- Vaultize Seal binds access rights and encryption to the file and revokes them in real time. Vaultize Share governs transfer through MFA-enabled links. Per-access telemetry feeds monitoring and incident evaluation. Vaultize Secure gives recovery a separate path.
- Evidence to retain
- Sealed rights and revocations. Transfer and recipient records. Access telemetry. Recovery events.
Criterion by criterion
What each criterion asks. What the file can answer.
Criterion identifiers and series names are from the AICPA Trust Services Criteria. Each description is a one-line paraphrase; read the criterion and its points of focus in the AICPA document. Each row is a capability mapping, not an auditor’s opinion.
Using this page
Where these rows fit in a SOC 2 examination.
A SOC 2 report is issued by a service auditor after examining your controls. This page is evidence for the criteria you map to.
- 1
Scope the system
Define the system and the categories the report will cover.
- 2
Map the controls
State which controls meet each criterion.
- 3
Operate and collect
Run the controls and keep the evidence. These rows belong here.
Bring the fifteen rows above as evidence for the criteria you map.
- 4
Auditor tests
Type 1 tests design at a point in time. Type 2 tests operation over a period.
- 5
Report issued
The auditor’s opinion goes to user entities and their auditors.
Responsibility boundary
Controls support the opinion. A product does not give it.
Vaultize contributes technical controls and evidence to a SOC 2 examination. It does not perform the examination, form the opinion, or decide which criteria apply. The opinion belongs to the service auditor. Read the criteria and obtain qualified advice before relying on this page.
Official references
Read the source before relying on the mapping.
Criterion identifiers and series names come from the first item. The others are the AICPA’s own SOC 2 material.
A practical next step
Bring your control matrix.
We will mark which criteria the governed file can evidence today. We will name the control owner responsible for the rest.
