All frameworks

SOC 2 — Trust Services Criteria

SOC 2 readiness assessment

Walk into your SOC 2 examination knowing your evidence holds up.

A catalogue of the Trust Services Criteria (57), organised by the five trust services categories.

57 criterion entries · versioned & change-controlled

Who it’s for

SaaS and service organisations preparing for a SOC 2 Type I or Type II examination, and the teams supporting them.

What readiness means for SOC 2

For SOC 2, readiness means your evidence supports the selected Trust Services Criteria ahead of an examination — Netallion supports the readiness stage; the examination itself is performed by a licensed CPA firm.

How Netallion handles it

Your SOC 2 readiness journey

  1. 1

    Scope the trust services

    Fix the system boundary and select which of the five categories — Security plus any of Availability, Confidentiality, Processing Integrity, Privacy — are in scope, so only the applicable criteria are assessed.

  2. 2

    Map controls to criteria

    Attach your control narratives and the system description to the criteria they support, with an owner and the control's stated frequency recorded.

  3. 3

    Assess operating evidence over the period

    For a Type II posture the question is not whether a control is described but whether it operated across the review window; we look for evidence spanning the period, not a single point in time.

  4. 4

    Surface blockers for auditor hand-off

    Criteria whose evidence is design-only, or thin over the period, become explicit blockers ranked ahead of the examination.

  5. 5

    Review & finalise

    An authorised assessor reviews the determinations and pins a readiness conclusion; the CPA examination itself is separate — Netallion does readiness, not the attestation.

The control library

What the SOC 2 library gives you

A catalogue of the Trust Services Criteria (57), organised by the five trust services categories.

A curated, versioned catalogue of this framework’s 57 criterion entries — with provenance — to collect, own, organise and track the currency of your evidence against.

From the field

Common SOC 2 blockers we find

Where evidence most often falls short — surfaced explicitly, not averaged away.

  • Controls are described in the system description but there is no operating evidence across the review period — a design-only posture that a Type II examination will not accept.
  • Change management evidences standard deployments but has no records for emergency or hotfix changes.
  • Subservice organisations are named but the complementary user-entity controls that depend on them are not evidenced.
  • Access reviews are scheduled quarterly but only one quarter of the period has evidence attached.

Evidence

The evidence you'll bring

You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:

Control environment

  • system description
  • org chart & role definitions
  • security policies
  • board/management oversight records

Change & operations

  • change tickets & approvals
  • deployment logs
  • access provisioning/deprovisioning records
  • SDLC evidence

Monitoring & logging

  • SIEM/alert records
  • log-review evidence
  • incident register
  • availability & backup monitoring

Vendor & TPRM

  • subservice-organisation list
  • vendor risk reviews
  • SOC reports from subservice providers
  • complementary user-entity controls

Start now — free

Prepare your SOC 2 evidence

Free — generate now

SOC 2 Readiness Kit

Netallion-authored templates and registers to prepare your SOC 2 evidence — generated instantly, no sign-up. Then organise that evidence in Netallion and assess whether it’s sufficient.

  • Trust Services Criteria mapping
  • System description template
  • Vendor assessment checklist
  • Readiness assessment worksheet

No email required. Free to download and use.

From evidence to a conclusion

How readiness is reached

The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.

  1. 1Scope

    The applicable requirement set for your framework and scope.

  2. 2Applicable requirements

    A fixed denominator — every in-scope requirement counts.

  3. 3Evidence

    You attach and own evidence; ownership and expiry are tracked.

  4. 4Evidence assessment

    The evidence is read against each requirement for sufficiency.

  5. 5Determination

    A requirement-level verdict with byte-verified citations.

  6. 6Blocker

    Negative findings surface as explicit blockers, not averages.

  7. 7Remediation

    Track the fix; reassessment — not a checkbox — resolves it.

  8. 8Review (R0–R3)

    Controlled human review with recorded provenance.

  9. 9Finalisation

    A signed, scope-pinned readiness conclusion.

  10. 10Report / export

    Readiness report, evidence index, SoA, audit ZIP + SHA-256.

  11. 11Lifecycle & reassessment

    Evidence expires/changes → affected requirements reopen.

Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.

What you get out

  • Requirement-level readiness across the 57 Trust Services Criteria in your selected categories
  • period-coverage view for a Type II posture
  • explicit blocker list with reasons
  • auditor-ready evidence index + audit ZIP with SHA-256 manifest

FAQ

SOC 2 readiness — common questions

Is SOC 2 a certification?

No — SOC 2 is an attestation examination performed by a licensed CPA firm under AICPA standards, resulting in a report. Netallion assesses readiness ahead of that examination; it does not perform or replace it.

Does Netallion cover all five Trust Services Categories?

Netallion maintains a catalogue of the Trust Services Criteria (57 criteria) across the five categories; you select the categories in scope for your report.

Can Netallion output map to my auditor's requests?

The readiness report and evidence index are structured to support an auditor hand-off — they support, rather than replace, the examination.

Related

Cross-framework leverage

Evidence you assemble for one framework often supports another. Commonly paired with:

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. A SOC 2 report is an attestation examination performed by a licensed CPA firm under AICPA standards — not a certification. Where the boundary sits.

See what your SOC 2 evidence proves

See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.