SOC 2 Suggested Control Library

SOC 2 Controls List: 94 Suggested Controls and Evidence Examples

Use this reference library to answer two practical questions: what should your team do, and what should you keep to prove it happened? Each guide includes a startup-friendly implementation, a scaled approach, evidence checks, audit record guidance, and a completion checklist.

Most teams should not implement all 94 examples. There is no official minimum or universal SOC 2 control list. Start with the downloadable 33-control lean starter set, then tailor it to your services, systems, risks, customer commitments, and examination scope with your service auditor.

Maintained by GreenHat Security · Reviewed August 21, 2026

Start Here

How to use this control library

Start with the job you need to do today. The downloadable 33-control set gives a lean starting point; the full 94-guide library is here when your scope or risk needs more depth.

I am implementing SOC 2 for the first time

Build the smallest control that can operate consistently

Name one owner, define the trigger and workflow, choose where the record will live, run one complete cycle, and fix anything the completion checklist exposes. You do not need a GRC platform to start.

I am gathering evidence for an audit

Start with the complete record set, not a few clean examples

Reconcile every in-scope occurrence from its source system, account for failures and exceptions, then trace selected records through approval, execution, result, and remediation.

  1. Step 1

    Set the scope

    Identify the services, systems, commitments, and Trust Services Categories included in the intended examination.

  2. Step 2

    Assign the work

    Choose one accountable owner, the people or systems that operate the control, a backup, and the expected timing.

  3. Step 3

    Run the workflow

    Put the control into the system your team already uses and complete one end-to-end cycle before relying on it.

  4. Step 4

    Keep the record

    Separate policy and design artifacts, approval and review records, and operating or technical evidence such as tickets, exports, logs, and screenshots.

  5. Step 5

    Test it yourself

    Build the complete audit record set, select one item, and verify that another person can reproduce the full trail.

Find a Control

Search and filter all 94 suggested controls.

Search by topic, suggested owner, operating cadence, or TSC identifier, then narrow the library to a domain. Criterion identifiers are cross-references only: one control may support several criteria, and one criterion may require several controls.

Showing 94 of 94 suggested controls

Governance

2 controls · 8 unique TSC IDs

Governance / Workforce

1 control · 4 unique TSC IDs

Service Commitments

9 controls · 14 unique TSC IDs

Implementation and evidence guide

Commitment Inventory

Customer-facing commitments are maintained in an approved register with owner, source, control mapping, applicability, review status, and evidence location.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.3CC3.1CC5.1
Open implementation guide

Implementation and evidence guide

Commitment Approval

New or changed customer-facing commitments are reviewed by business, legal, security, engineering, and service owners before external use.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.3CC3.1CC5.1CC5.3
Open implementation guide

Implementation and evidence guide

Shared Responsibility Definition

Customer, the organization, and relevant third-party responsibilities are documented for security, availability, data handling, integrations, monitoring, support, and response.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.3CC9.2A1.2C1.1+1
Open implementation guide

Implementation and evidence guide

Service Description Accuracy

Service descriptions, RFP responses, and assurance materials accurately describe implemented capabilities, limitations, dependencies, and customer obligations.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.3CC5.3
Open implementation guide

Implementation and evidence guide

Operational Dependency Management

Dependencies required to meet commitments are identified, assigned owners, monitored, and linked to supporting controls and procedures.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC3.2CC9.1CC9.2A1.2
Open implementation guide

Implementation and evidence guide

Availability and Support Expectations

Availability, monitoring, backup, recovery, support, and escalation expectations are defined, measured where applicable, and reviewed.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.3A1.1A1.2
Open implementation guide

Implementation and evidence guide

Change and Notification Governance

Material changes to commitments, responsibility boundaries, or service capabilities follow controlled review and customer notification requirements where applicable.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.3CC8.1
Open implementation guide

Implementation and evidence guide

Exception and Risk Acceptance

Commitment exceptions, deviations, unsupported customer assumptions, and service limitations are documented, approved, and tracked.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC3.2CC4.2CC5.1
Open implementation guide

Implementation and evidence guide

Commitment Evidence Retention

Commitment approval records, registers, shared-responsibility matrices, customer-facing materials, and monitoring evidence are retained for SOC 2 support.

Suggested owner
Service Owner / Legal / CISO
Operating cadence
Ongoing; review at least annually
CC2.1CC5.3
Open implementation guide

Risk Management

1 control · 4 unique TSC IDs

Risk Management / Monitoring

1 control · 4 unique TSC IDs

Vendor Risk

10 controls · 18 unique TSC IDs

Implementation and evidence guide

Vendor Inventory

All vendors and third parties are recorded in an approved inventory with owner, service description, data access, customer impact, contract status, review dates, and risk tier.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC9.2
Open implementation guide

Implementation and evidence guide

Vendor Risk Classification

Vendors are classified based on data sensitivity, production access, availability dependency, customer impact, and control reliance.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC3.2CC9.2
Open implementation guide

Implementation and evidence guide

Due Diligence and Security Review

Critical and high-risk vendors undergo security review before onboarding and periodically thereafter.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC9.2P6.4
Open implementation guide

Implementation and evidence guide

Contractual Security Requirements

Vendor contracts include confidentiality, security, access, data handling, incident notification, subprocessor, return/destruction, and termination obligations where applicable.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC6.4CC6.5CC9.2C1.1+2
Open implementation guide

Implementation and evidence guide

Third-Party Access Governance

Vendor access follows least privilege, MFA where feasible, approved connection methods, logging, and prompt revocation when no longer needed.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC6.1CC6.2CC6.3CC9.2
Open implementation guide

Implementation and evidence guide

Ongoing Vendor Monitoring

Critical and high-risk vendors are reassessed and monitored based on risk, incidents, service changes, contract renewals, and control reliance.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC4.1CC9.2A1.2
Open implementation guide

Implementation and evidence guide

Subprocessor and Data Processing Governance

Subprocessors and data-processing vendors are approved, tracked, and governed according to customer commitments and data protection obligations.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC9.2P6.4P6.5
Open implementation guide

Implementation and evidence guide

Vendor Incident and Service Disruption Notification

Vendors provide timely notification of incidents, security events, data exposure, and material service disruptions that may affect the organization.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC7.4CC9.2P6.5P6.6
Open implementation guide

Implementation and evidence guide

Vendor Offboarding and Termination

Vendor access, integrations, credentials, data retention, return/destruction obligations, and offboarding evidence are addressed during termination.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC6.2CC6.5CC9.2C1.2+1
Open implementation guide

Implementation and evidence guide

Vendor Risk Evidence Retention

Vendor risk evidence is retained for SOC 2 audit support, customer assurance, management review, and ongoing monitoring.

Suggested owner
Vendor Risk Owner / CISO / Legal
Operating cadence
Prior to onboarding; periodic based on risk; at least annually for critical/high
CC2.1CC5.3CC9.2
Open implementation guide

Workforce Security

5 controls · 8 unique TSC IDs

Implementation and evidence guide

Workforce Roles and Ownership

Roles, responsibilities, reporting lines, and ownership for engineering, security operations, product, support, incident response, privacy, and compliance are documented and maintained.

Suggested owner
HR Owner / IT / CISO
Operating cadence
Upon hire/change/termination; annual as applicable
CC1.3CC1.4CC1.5
Open implementation guide

Implementation and evidence guide

Workforce Screening

Background or reference checks are completed where legally permitted and appropriate based on role, responsibility, and access level.

Suggested owner
HR Owner / IT / CISO
Operating cadence
Upon hire/change/termination; annual as applicable
CC1.4
Open implementation guide

Implementation and evidence guide

Security and Privacy Awareness Training

Personnel and contractors complete security and privacy awareness training during onboarding and at least annually thereafter.

Suggested owner
HR Owner / IT / CISO
Operating cadence
Upon hire/change/termination; annual as applicable
CC1.4CC1.5CC2.2P8.1
Open implementation guide

Implementation and evidence guide

Workforce Competency and Performance Review

Management periodically evaluates personnel competency and performance for security, confidentiality, privacy, customer commitments, and control ownership.

Suggested owner
HR Owner / IT / CISO
Operating cadence
Upon hire/change/termination; annual as applicable
CC1.4CC1.5
Open implementation guide

Implementation and evidence guide

Workforce Offboarding and Asset Recovery

Access and company assets are removed or recovered when personnel leave, change roles, or no longer require access.

Suggested owner
HR Owner / IT / CISO
Operating cadence
Upon hire/change/termination; annual as applicable
CC1.5CC6.2CC6.3CC6.5
Open implementation guide

Asset, Data & Architecture

6 controls · 14 unique TSC IDs

Implementation and evidence guide

Service Asset Inventory

Assets supporting service delivery are inventoried with owner, environment, location, lifecycle status, classification, criticality, customer data role, and review date.

Suggested owner
Engineering / Infrastructure / Data Owner
Operating cadence
Quarterly for production/customer-impacting; annually for supporting assets
CC2.1CC6.1CC7.1C1.1
Open implementation guide

Implementation and evidence guide

Architecture and Data Flow Documentation

Critical data flows, repositories, integrations, trust boundaries, customer-data processing paths, and AI/LLM data flows are documented and maintained.

Suggested owner
Engineering / Infrastructure / Data Owner
Operating cadence
Quarterly for production/customer-impacting; annually for supporting assets
CC2.1CC3.2CC5.2C1.1+1
Open implementation guide

Implementation and evidence guide

Customer Data Classification

Customer data and telemetry are classified and protected according to sensitivity, contractual commitments, privacy obligations, and operational use.

Suggested owner
Engineering / Infrastructure / Data Owner
Operating cadence
Quarterly for production/customer-impacting; annually for supporting assets
CC2.1C1.1P3.1P4.1+1
Open implementation guide

Implementation and evidence guide

Confidentiality and Retention Requirements

Retention periods, disposal methods, and confidentiality handling rules are approved and maintained by data category.

Suggested owner
Engineering / Infrastructure / Data Owner
Operating cadence
Quarterly for production/customer-impacting; annually for supporting assets
C1.1C1.2P4.2P4.3
Open implementation guide

Implementation and evidence guide

Secure Disposal and Deletion

Confidential information, customer data, system data, and personal information are deleted, anonymized, or rendered unrecoverable when no longer required or upon authorized request.

Suggested owner
Engineering / Infrastructure / Data Owner
Operating cadence
Quarterly for production/customer-impacting; annually for supporting assets
CC6.5C1.2P4.3
Open implementation guide

Implementation and evidence guide

Critical Asset and High-Value Target Tagging

Assets critical to service delivery, customer isolation, detection integrity, privileged access, evidence generation, recovery, or customer commitments are tagged as critical/high-value and reviewed based on risk.

Suggested owner
Engineering / Infrastructure / Data Owner
Operating cadence
Quarterly for production/customer-impacting; annually for supporting assets
CC2.1CC3.2CC7.1A1.1
Open implementation guide

Change Management

6 controls · 7 unique TSC IDs

Implementation and evidence guide

Change Documentation and Traceability

Each production-impacting change has a ticket-of-record with business/security rationale, affected systems, approver, test evidence, deployment evidence, and rollback plan.

Suggested owner
Head of Engineering / Platform Owner
Operating cadence
Per change
CC8.1
Open implementation guide

Implementation and evidence guide

Peer Review and Approval

Production-bound code, configuration, detection logic, infrastructure, and AI/LLM workflow changes require peer review and authorized approval before deployment.

Suggested owner
Head of Engineering / Platform Owner
Operating cadence
Per change
CC8.1
Open implementation guide

Implementation and evidence guide

Secure SDLC and Threat Modeling

New features and material architecture changes undergo security review and threat modeling proportionate to customer data, authorization, encryption, tenant isolation, and availability risk.

Suggested owner
Head of Engineering / Platform Owner
Operating cadence
Per change
CC3.2CC5.2CC8.1
Open implementation guide

Implementation and evidence guide

Automated Testing and Security Scanning

Automated build, unit/integration/smoke testing, dependency, secret, SAST, IaC, and container/image scanning are run before release where feasible.

Suggested owner
Head of Engineering / Platform Owner
Operating cadence
Per change
CC7.1CC8.1
Open implementation guide

Implementation and evidence guide

Controlled Production Deployment

Deployments are performed by authorized personnel or approved CI/CD pipelines and are logged with traceability to approved changes and post-deployment validation.

Suggested owner
Head of Engineering / Platform Owner
Operating cadence
Per change
CC6.1CC8.1
Open implementation guide

Implementation and evidence guide

Environment Separation

Development, test, staging, production, and recovery environments are logically separated; production customer data is not used in lower environments unless formally approved and protected.

Suggested owner
Head of Engineering / Platform Owner
Operating cadence
Per change
CC6.1CC8.1C1.1P4.1
Open implementation guide

AI / LLM Governance

8 controls · 15 unique TSC IDs

Implementation and evidence guide

AI/LLM Workflow Inventory and Ownership

AI/LLM workflows are inventoried, assigned owners, classified by use case and risk, and reviewed for approved production use.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC2.1CC3.2CC5.2C1.1+1
Open implementation guide

Implementation and evidence guide

Approved Use Cases and Human Review

AI/LLM outputs affecting customer-facing communications, incident decisions, security recommendations, or automated actions require defined human review.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC5.1CC8.1P8.1
Open implementation guide

Implementation and evidence guide

Data Handling and Customer Context Boundaries

Customer data, telemetry, secrets, credentials, regulated data, and confidential policy context are controlled, minimized, and restricted by approved workflow purpose.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC6.1CC6.7C1.1P4.1
Open implementation guide

Implementation and evidence guide

Retrieval Source and Policy Context Governance

Retrieval sources, embeddings, memory, policy context, and customer context are authorized, versioned, and reviewed for accuracy and confidentiality.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC2.1CC8.1C1.1P7.1
Open implementation guide

Implementation and evidence guide

Tool and Action Guardrails

AI/LLM workflows with tools, scripts, API calls, ticketing, firewall exports, or customer-impacting actions use least privilege, approval gates, and kill-switch controls.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC6.1CC7.4CC8.1
Open implementation guide

Implementation and evidence guide

Prompt, Model, and Configuration Change Control

Prompt, model, tool, retrieval, system-message, and workflow changes follow controlled change-management procedures.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC8.1
Open implementation guide

Implementation and evidence guide

Output Validation and Evidence

AI/LLM-generated outputs are reviewed for grounding, accuracy, sensitive data, hallucination risk, and evidence traceability before operational reliance.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC2.1CC7.3P8.1
Open implementation guide

Implementation and evidence guide

AI Audit Logging and Retention

Material AI/LLM workflow activity, configuration, approvals, outputs, review records, and exceptions are logged and retained as SOC 2 evidence.

Suggested owner
AI Workflow Owner / CISO / Engineering
Operating cadence
Per workflow/change; review at least annually
CC7.2CC7.3CC5.3
Open implementation guide

Logical Access

7 controls · 12 unique TSC IDs

Implementation and evidence guide

Administrative Access Monitoring

Administrative and privileged access is approved, least-privileged, logged, reviewed, and monitored; privileged activity and access changes are retained as evidence.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.1CC6.2CC6.3CC7.2
Open implementation guide

Implementation and evidence guide

Customer Authentication and Authorization

Customer access enforces strong authentication, role-based authorization, and customer/tenant boundaries for portals, reports, evidence, and administrative roles.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.1CC6.2CC6.3CC6.6
Open implementation guide

Implementation and evidence guide

Privileged Access Approval

New or modified privileged access to production systems, cloud environments, repositories, security tooling, and customer-facing administrative functions is approved by an authorized owner or manager.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.2CC6.3CC5.3
Open implementation guide

Implementation and evidence guide

Least Privilege Access Design

Access is assigned based on least privilege, role, business need, environment, customer assignment, and data classification.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.1CC6.3CC5.2
Open implementation guide

Implementation and evidence guide

Periodic Access Review and Recertification

Workforce, privileged, customer-support, service-account, administrative, and third-party access is reviewed on a defined cadence with evidence of owner approval, remediation, and closure.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.2CC6.3CC4.1CC4.2
Open implementation guide

Implementation and evidence guide

Timely Access Removal

Access to critical systems is removed or modified within defined timelines after termination, role change, contract completion, or loss of business need.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.2CC6.3CC6.5
Open implementation guide

Implementation and evidence guide

Secrets and Service Credential Management

Service accounts, API keys, tokens, certificates, automation credentials, and privileged secrets are inventoried where feasible, least-privileged, protected, rotated or reviewed based on risk, and removed when no longer required.

Suggested owner
IT / Infrastructure Owner / System Owners
Operating cadence
Per request/change; periodic review quarterly/annually by risk
CC6.1CC6.6CC6.7C1.1
Open implementation guide

Security Architecture

8 controls · 12 unique TSC IDs

Implementation and evidence guide

Customer Environment Isolation

Access controls, tenant identifiers, data stores, dashboards, APIs, reports, retrieval sources, and automation preserve customer boundaries and prevent unauthorized cross-customer access.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.1CC6.6C1.1P4.1
Open implementation guide

Implementation and evidence guide

Cloud and Container Security Baselines

Cloud services, organization-managed private cloud/container hosts, registries, images, and runtime environments follow approved secure configuration baselines.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC5.2CC6.1CC7.1
Open implementation guide

Implementation and evidence guide

Network Boundary and Segmentation Controls

Network boundaries, production networks, customer integration paths, VPN access, security groups, firewalls, and WAF-equivalent controls restrict traffic to approved paths.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.6CC6.7CC7.1
Open implementation guide

Implementation and evidence guide

Encryption and Key Management

Sensitive data, telemetry, logs, backups, administrative sessions, secrets, and keys are protected through approved encryption and key-management controls.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.1CC6.7C1.1
Open implementation guide

Implementation and evidence guide

Endpoint Security Baseline

Company-managed endpoints accessing critical systems meet a security baseline including full-disk encryption, screen lock, endpoint protection, secure configuration, and approved management tooling.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.7CC6.8CC7.1
Open implementation guide

Implementation and evidence guide

Malware and Unauthorized Software Control

Anti-malware and endpoint detection are deployed and monitored on endpoints and supported production workloads, and unauthorized software is prevented, detected, and responded to.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.8CC7.1CC7.2
Open implementation guide

Implementation and evidence guide

Cloud Security Posture Monitoring

Cloud, container, network, and infrastructure configurations are monitored for insecure settings, exposed services, privilege drift, image risk, and deviations from approved baselines.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.6CC7.1CC7.2
Open implementation guide

Implementation and evidence guide

Physical Access and Device Protection

Physical access to company facilities is restricted; hosting provider physical/environmental controls are relied upon and reviewed; company devices are recovered or securely disabled when no longer required.

Suggested owner
Infrastructure / Security Operations / IT
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.4CC6.5A1.2
Open implementation guide

System Operations

8 controls · 12 unique TSC IDs

Implementation and evidence guide

Security Logging and Monitoring Evidence

Required logs, review activities, retention requirements, integrity controls, and evidence production expectations are defined and implemented for security, operational, audit, and customer-support records.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC2.1CC7.2CC7.3CC5.3
Open implementation guide

Implementation and evidence guide

Availability and Performance Monitoring

AOT availability, ingestion health, telemetry latency, processing capacity, storage pressure, alerting thresholds, and customer-facing monitoring commitments are measured and escalated when thresholds are exceeded.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC7.2A1.1
Open implementation guide

Implementation and evidence guide

Security Alert Triage

Threat-stream alerts, anomalous activity, malicious indicators, AOT detections, and system-generated findings are reviewed, prioritized, assigned, escalated, and closed based on severity, confidence, customer impact, and commitments.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC7.2CC7.3
Open implementation guide

Implementation and evidence guide

Threat Intelligence Intake

Threat intelligence sources are selected, evaluated, approved, operationalized, versioned, and periodically reviewed before they influence detection logic, enrichment, notifications, or recommendations.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC2.1CC2.3CC7.2CC7.3
Open implementation guide

Implementation and evidence guide

Vulnerability Scanning

Infrastructure, cloud resources, containers, endpoints, applications, external-facing services, and supporting components are scanned or assessed for vulnerabilities and misconfigurations based on risk and cadence.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.8CC7.1CC7.2
Open implementation guide

Implementation and evidence guide

Vulnerability Remediation

Findings are prioritized by severity, exploitability, exposure, customer impact, and ownership; unresolved items require remediation, exception, compensating control, or formal risk acceptance.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC4.2CC6.8CC7.1CC7.2
Open implementation guide

Implementation and evidence guide

Detection Rule and Hypothesis Testing Review

Changes to detection logic, threat hypotheses, real-time processing algorithms, correlation rules, risk scoring, escalation logic, and customer-facing outputs are reviewed and tested before production release.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC7.1CC8.1
Open implementation guide

Implementation and evidence guide

Automated Mitigation and Kill Switch Guardrails

Automated or one-click mitigation features are restricted, logged, authorized, reversible where practical, and protected by safeguards that limit unauthorized or excessive customer impact.

Suggested owner
Security Operations / Engineering / Infrastructure
Operating cadence
Continuous/ongoing; periodic review by risk
CC6.1CC7.4CC8.1
Open implementation guide

Availability / Resilience

4 controls · 6 unique TSC IDs

Implementation and evidence guide

Capacity and Scalability Planning

Monitoring includes capacity, scalability, ingestion health, storage pressure, queue/backlog indicators, and service health signals needed to identify resilience risk and trigger remediation.

Suggested owner
Operations Lead / Infrastructure Owner
Operating cadence
Continuous for backups/monitoring; quarterly/annual testing as defined
A1.1
Open implementation guide

Implementation and evidence guide

Backup and Recovery

Production data stores, configuration repositories, critical code repositories, evidence artifacts, logs, and recovery runbooks are backed up or replicated, protected, monitored, and recoverable according to criticality tier.

Suggested owner
Operations Lead / Infrastructure Owner
Operating cadence
Continuous for backups/monitoring; quarterly/annual testing as defined
A1.2C1.1C1.2
Open implementation guide

Implementation and evidence guide

Recovery Testing

Tier 0 and Tier 1 recovery procedures are tested at least annually and high-value backups are sampled for restore or validation at least quarterly unless an approved alternate cadence exists.

Suggested owner
Operations Lead / Infrastructure Owner
Operating cadence
Continuous for backups/monitoring; quarterly/annual testing as defined
A1.3
Open implementation guide

Implementation and evidence guide

Business Continuity Dependency Management

Critical dependencies for services are maintained with owner, service purpose, recovery relevance, customer impact, alternatives, backup personnel, and continuity procedures.

Suggested owner
Operations Lead / Infrastructure Owner
Operating cadence
Continuous for backups/monitoring; quarterly/annual testing as defined
CC9.1A1.2
Open implementation guide

Incident Response

4 controls · 8 unique TSC IDs

Implementation and evidence guide

Incident Response Plan

The incident response plan defines roles, escalation paths, severity levels, communication procedures, containment steps, recovery responsibilities, and required evidence for security and availability incidents.

Suggested owner
CISO / Incident Commander / Privacy-Legal Owner
Operating cadence
Per event/incident; tabletop at least annually
CC7.3CC7.4CC7.5
Open implementation guide

Implementation and evidence guide

Incident Classification and Escalation

Security events are classified as events, incidents, privacy events, availability failures, customer-impacting events, or service-commitment failures and escalated based on severity.

Suggested owner
CISO / Incident Commander / Privacy-Legal Owner
Operating cadence
Per event/incident; tabletop at least annually
CC7.3CC7.4
Open implementation guide

Implementation and evidence guide

Containment, Remediation, and Root Cause

Incidents require containment, investigation, remediation, recovery validation, root-cause analysis, corrective actions, and post-incident review where appropriate.

Suggested owner
CISO / Incident Commander / Privacy-Legal Owner
Operating cadence
Per event/incident; tabletop at least annually
CC7.4CC7.5CC4.2
Open implementation guide

Implementation and evidence guide

Customer and Regulatory Notification

Customer, regulator, law-enforcement, data-subject, contractual, vendor, and privacy notification obligations are evaluated, approved, executed where required, and retained.

Suggested owner
CISO / Incident Commander / Privacy-Legal Owner
Operating cadence
Per event/incident; tabletop at least annually
CC2.3CC7.4P6.3P6.5+1
Open implementation guide

Processing Integrity

5 controls · 5 unique TSC IDs

Implementation and evidence guide

Processing Objectives and Specifications

The organization defines what correct processing looks like for each critical in-scope flow, including its data sources, rules, expected results, timing targets, dependencies, owners, and customer responsibilities, and communicates current specifications and material changes to affected teams and customers.

Suggested owner
Product Owner / Engineering Owner
Operating cadence
At least annually and upon material change
PI1.1
Open implementation guide

Implementation and evidence guide

Input Validation and Intake Reconciliation

In-scope services accept data only from expected sources and in valid formats, detect missing, duplicate, late, partial, or unauthorized inputs, and route rejected or questionable records for resolution.

Suggested owner
Application Engineering / Data Operations
Operating cadence
Continuous or per intake; exceptions reviewed at least weekly
PI1.2
Open implementation guide

Implementation and evidence guide

Processing Execution and Exception Handling

In-scope workflows apply approved rules in the intended sequence, compare expected and actual counts or results, detect failed, inaccurate, partial, duplicate, or out-of-order processing, and track correction or reprocessing through closure.

Suggested owner
Application Engineering / Service Operations
Operating cadence
Continuous or per execution; exceptions reviewed at least weekly
PI1.3
Open implementation guide

Implementation and evidence guide

Output Validation and Delivery

Outputs from critical processing flows are checked against expected content, control totals, timing, and destination rules, released only to intended recipients, and monitored for inaccurate, missing, late, duplicate, failed, or unauthorized delivery.

Suggested owner
Product Operations / Application Engineering
Operating cadence
Continuous or per delivery; exceptions reviewed at least weekly
PI1.4
Open implementation guide

Implementation and evidence guide

Stored Processing Data Integrity

Inputs, work-in-progress records, and completed outputs used by critical flows are stored with controls that detect unauthorized change, loss, incomplete state, and improper retention, archival, or deletion.

Suggested owner
Platform Engineering / Data Owner
Operating cadence
Continuous; configuration and integrity review at least quarterly
PI1.5
Open implementation guide

Confidentiality / Privacy

9 controls · 25 unique TSC IDs

Implementation and evidence guide

Privacy Governance and Notice

Privacy responsibilities, data handling expectations, customer commitments, notices, processing purposes, and authorized uses are defined, reviewed, and communicated to data subjects/customers as applicable.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
CC2.3P1.1P2.1
Open implementation guide

Implementation and evidence guide

Collection and Use Limitation

Personal information and customer confidential information are collected and used only for approved business, security, service delivery, support, legal, or contractual purposes.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
P3.1P4.1P4.2P7.1
Open implementation guide

Implementation and evidence guide

Data Subject / Customer Request Handling

Requests involving access, correction, deletion, export, restriction, accounting, or customer-directed handling are logged, validated, fulfilled or escalated, and retained.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
P4.3P5.1P5.2P6.7+1
Open implementation guide

Implementation and evidence guide

Consent, Choice, and Disclosure Management

Choices, consent, and disclosure requirements for personal information are communicated, obtained where required, recorded, and reflected in approved data processing workflows.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
P2.1P3.2P6.1P6.2
Open implementation guide

Implementation and evidence guide

Privacy Incident Handling

Privacy events and suspected unauthorized disclosures receive privacy-specific review, evidence handling, legal/compliance consultation, notification tracking, and corrective actions.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
P6.3P6.6P8.1CC7.4
Open implementation guide

Implementation and evidence guide

Confidentiality Classification

Data classification and handling rules define Confidential, Restricted, Customer Confidential, Internal, and Public information treatment and support identification of confidential information.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
CC2.1C1.1
Open implementation guide

Implementation and evidence guide

Encryption and Protection

Confidential information is protected in transit and at rest using approved encryption, access control, segmentation, logging, and key-management practices.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
CC6.7C1.1
Open implementation guide

Implementation and evidence guide

Retention and Disposal

Confidential information is retained only as required for business, legal, customer, security, or audit purposes and disposed of using approved methods.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
C1.2P4.2P4.3
Open implementation guide

Implementation and evidence guide

Third-Party Confidentiality

Third parties are authorized, contractually bound, and reviewed before receiving or processing confidential information.

Suggested owner
Privacy Owner / CISO / Data Owners
Operating cadence
Ongoing; periodic review by privacy/data owner
CC9.2C1.1P6.4P6.5
Open implementation guide
Field Guide

Control library field glossary

Owner
The role or team expected to be accountable for operating or overseeing the example control.
Cadence
The event-driven or recurring timing at which the control activity is expected to occur.
Control type
A practical classification indicating whether an activity is manual, automated, IT-dependent, or entity-level.
Evidence
Policy and design artifacts define the control; approvals show authorization or review; operating and technical records show what actually happened.
Audit record set
Every in-scope occurrence during the relevant date or period. Auditors often call this the population.
TSC reference
A navigation mapping to a Trust Services Criteria identifier, not a statement of complete criterion coverage.
Common Questions

Common questions about SOC 2 controls

Does SOC 2 require 94 controls or the 33 in the workbook?

No. The 94 guides are optional reference examples, and the 33-control workbook is a lean suggested starting point, not an official minimum. Your scope, risks, system description, commitments, and selected criteria determine the controls you need.

Can one control support several TSC references?

Yes. A well-designed activity may support more than one criterion, while a single criterion may also require several complementary controls. Mappings should be validated in context.

Are the evidence examples automatically sufficient?

No. Evidence must match the tailored control, period, systems, and population. A service auditor determines the procedures and evidence needed for the engagement.

How should I organize SOC 2 evidence?

Keep policy and design artifacts separate from approval and review records, then link the operating or technical proof: screenshots, exports, logs, tickets, reports, test results, and resolved exceptions.

Sources and Limitations

Methodology, sources, and limitations

GreenHat Security maintains these guides to help operating teams turn a control outcome into an owner, workflow, evidence trail, complete audit record set, and self-test. Trust Services Criteria identifiers are included only as navigation references; the guides do not reproduce AICPA criterion descriptions, points of focus, or an AICPA audit program.

Each guide combines a suggested control outcome with practical implementation steps, evidence-quality checks, record-set guidance, likely testing procedures, and common gaps. The small-company and scaled approaches illustrate possible operating models; tailor the maturity and tools to your environment.

These are educational suggestions, not official AICPA criteria, legal or accounting advice, an audit conclusion, or a guarantee of examination results. Tailor every control to your scope, risks, systems, and commitments, then confirm final mappings and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.