SOC 2 — Trust Services Criteria
SOC 2 readiness assessment
Walk into your SOC 2 examination knowing your evidence holds up.
A catalogue of the Trust Services Criteria (57), organised by the five trust services categories.
57 criterion entries · versioned & change-controlled
Who it’s for
SaaS and service organisations preparing for a SOC 2 Type I or Type II examination, and the teams supporting them.
What readiness means for SOC 2
For SOC 2, readiness means your evidence supports the selected Trust Services Criteria ahead of an examination — Netallion supports the readiness stage; the examination itself is performed by a licensed CPA firm.
How Netallion handles it
Your SOC 2 readiness journey
- 1
Scope the trust services
Fix the system boundary and select which of the five categories — Security plus any of Availability, Confidentiality, Processing Integrity, Privacy — are in scope, so only the applicable criteria are assessed.
- 2
Map controls to criteria
Attach your control narratives and the system description to the criteria they support, with an owner and the control's stated frequency recorded.
- 3
Assess operating evidence over the period
For a Type II posture the question is not whether a control is described but whether it operated across the review window; we look for evidence spanning the period, not a single point in time.
- 4
Surface blockers for auditor hand-off
Criteria whose evidence is design-only, or thin over the period, become explicit blockers ranked ahead of the examination.
- 5
Review & finalise
An authorised assessor reviews the determinations and pins a readiness conclusion; the CPA examination itself is separate — Netallion does readiness, not the attestation.
The control library
What the SOC 2 library gives you
A catalogue of the Trust Services Criteria (57), organised by the five trust services categories.
A curated, versioned catalogue of this framework’s 57 criterion entries — with provenance — to collect, own, organise and track the currency of your evidence against.
From the field
Common SOC 2 blockers we find
Where evidence most often falls short — surfaced explicitly, not averaged away.
- Controls are described in the system description but there is no operating evidence across the review period — a design-only posture that a Type II examination will not accept.
- Change management evidences standard deployments but has no records for emergency or hotfix changes.
- Subservice organisations are named but the complementary user-entity controls that depend on them are not evidenced.
- Access reviews are scheduled quarterly but only one quarter of the period has evidence attached.
Evidence
The evidence you'll bring
You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:
Control environment
- system description
- org chart & role definitions
- security policies
- board/management oversight records
Change & operations
- change tickets & approvals
- deployment logs
- access provisioning/deprovisioning records
- SDLC evidence
Monitoring & logging
- SIEM/alert records
- log-review evidence
- incident register
- availability & backup monitoring
Vendor & TPRM
- subservice-organisation list
- vendor risk reviews
- SOC reports from subservice providers
- complementary user-entity controls
Start now — free
Prepare your SOC 2 evidence
Free — generate now
SOC 2 Readiness Kit
Netallion-authored templates and registers to prepare your SOC 2 evidence — generated instantly, no sign-up. Then organise that evidence in Netallion and assess whether it’s sufficient.
- Trust Services Criteria mapping
- System description template
- Vendor assessment checklist
- Readiness assessment worksheet
No email required. Free to download and use.
From evidence to a conclusion
How readiness is reached
The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.
- 1Scope
The applicable requirement set for your framework and scope.
- 2Applicable requirements
A fixed denominator — every in-scope requirement counts.
- 3Evidence
You attach and own evidence; ownership and expiry are tracked.
- 4Evidence assessment
The evidence is read against each requirement for sufficiency.
- 5Determination
A requirement-level verdict with byte-verified citations.
- 6Blocker
Negative findings surface as explicit blockers, not averages.
- 7Remediation
Track the fix; reassessment — not a checkbox — resolves it.
- 8Review (R0–R3)
Controlled human review with recorded provenance.
- 9Finalisation
A signed, scope-pinned readiness conclusion.
- 10Report / export
Readiness report, evidence index, SoA, audit ZIP + SHA-256.
- 11Lifecycle & reassessment
Evidence expires/changes → affected requirements reopen.
Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.
What you get out
- Requirement-level readiness across the 57 Trust Services Criteria in your selected categories
- period-coverage view for a Type II posture
- explicit blocker list with reasons
- auditor-ready evidence index + audit ZIP with SHA-256 manifest
FAQ
SOC 2 readiness — common questions
Is SOC 2 a certification?
No — SOC 2 is an attestation examination performed by a licensed CPA firm under AICPA standards, resulting in a report. Netallion assesses readiness ahead of that examination; it does not perform or replace it.
Does Netallion cover all five Trust Services Categories?
Netallion maintains a catalogue of the Trust Services Criteria (57 criteria) across the five categories; you select the categories in scope for your report.
Can Netallion output map to my auditor's requests?
The readiness report and evidence index are structured to support an auditor hand-off — they support, rather than replace, the examination.
Related
Cross-framework leverage
Evidence you assemble for one framework often supports another. Commonly paired with:
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. A SOC 2 report is an attestation examination performed by a licensed CPA firm under AICPA standards — not a certification. Where the boundary sits.
See what your SOC 2 evidence proves
See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.