🇺🇸 SOC 2 · AICPA TSC
SOC 2 readiness scoping for B2B SaaS Free. 2 minutes. Engineer-led.
SOC 2 is the enterprise sales unblock for B2B SaaS. The audit firm signs the report; the engineering team has to build the evidence trail. Get a clean list of which Trust Services Criteria apply, what controls you need, and which can be inherited from your cloud vendor.
In scope
What this covers
- 01 Trust Services Criteria — Security (mandatory), Availability, Confidentiality, Processing Integrity, Privacy
- 02 Type I vs Type II — point-in-time design vs ongoing operation over 3-12 months
- 03 Common Criteria 1-9 — control environment, communication, risk assessment, monitoring, control activities, logical access, system operations, change management, risk mitigation
- 04 Vendor SOC 2 inheritance — AWS, GCP, Azure, Stripe carry their own reports; inherit, don't re-audit
- 05 Audit firm process — readiness assessment, observation window, fieldwork, report
- 06 Bridge letters — for periods between audit reports
- 07 Customer Security Questionnaires — common SOC 2 mapping (CAIQ, SIG, custom)
For · CTO / Head of Engineering at B2B SaaS closing 5-6 figure deals where security review blocks renewals