About this content
The SOC 2 framework in Compliance in a Box is built on the 2017 Trust Services Criteria, with the 2022 revised points of focus. When you generate the compliance pages, the app creates a policy page for each policy and an activity page for each recurring activity in the categories you chose, and maps each of them to SOC 2 criteria. This chapter lists all of it, as shipped in framework version 1.
The criteria descriptions on this page are short labels in our own words, not the AICPA's criteria text. Use the criterion IDs to look up the official wording.
Important: the policy and activity templates are a starting point, not legal or audit advice. Review each one and adapt it to how your company actually works before you approve it. The criteria mappings are an initial, indicative mapping: have your auditor review them. Using the app does not by itself make your company SOC 2 compliant, and it does not replace an independent auditor. SOC 2 and the Trust Services Criteria are AICPA frameworks; Compliance in a Box is not affiliated with or endorsed by the AICPA.
Trust Services Categories
When you generate the compliance pages (Settings → Frameworks & pages), you choose which Trust Services Categories your SOC 2 report covers. Security is always included. The other four are optional. A policy or activity is included when any of its categories is selected, so a page shared by Security and another category is always there.
| Category | Required? | What it adds |
|---|---|---|
| Security | Always included | 20 policies and 13 recurring activities, plus the criteria CC1.1 to CC9.2 in the controls matrix. |
| Availability | Optional | 2 policies (Backup Policy; Capacity & Performance Management Policy) and 2 activities (Business Continuity / DR Test; Backup Restore Test), plus criteria A1.1 to A1.3. |
| Confidentiality | Optional | No extra pages: its policies (Data Classification & Handling; Data Retention & Disposal) are already part of Security. Adds criteria C1.1 and C1.2 to the controls matrix. |
| Processing Integrity | Optional | 1 policy (Data Processing Integrity Policy), plus criteria PI1.1 to PI1.5. |
| Privacy | Optional | 1 policy (Privacy Policy), plus criteria P1.1 to P8.1. |
With Security only, the app creates 41 pages (8 structure and report pages, 20 policies, 13 activities). With all five categories, it creates 47 (8 structure and report pages, 24 policies, 15 activities).
Note: you can add categories later and generate again; the app only creates the pages that are missing. Categories can't be removed once their pages exist. See Administration.
The page tree
Everything lives in the one compliance space the app manages. The space home page is titled with your company name. The tree below shows every page the app provisions; pages marked "optional category" appear only if that category is selected.
- <Company> Compliance Program (space home: an overview of the program and how to use the space)
- Policies
- One page per policy in scope (see Policies)
- Recurring Activities
- One page per activity, titled with its cadence, for example "User Access Review (Quarterly)"
- One evidence page per period, created ahead of its due date, for example "User Access Review — 2026 Q3" (or "— FY2027 Q1" when your fiscal year doesn't start in January)
- One page per activity, titled with its cadence, for example "User Access Review (Quarterly)"
- Controls Matrix — SOC 2 (generated)
- Evidence & Reports
- Policy Approval Log (generated), with one page per year, for example "Policy Approval Log — 2026"
- Policy Acknowledgement Report (generated), with one page per year
- Activity Completion Report (generated), with one page per year
- Audit Log (generated; created by the first report refresh), with one page per month, for example "Audit Log — September 2026"
- Weekly compliance summary (generated; only when the weekly summary reminder is in use)
- Compliance Tasks (only when reminders are in use), with one private task page per person
- Policies
Generated pages are rebuilt by the app from its records, daily and on demand, so edits to them are overwritten. Report pages are restricted to Compliance Admins (and the Auditors group, if you set one). Policy, activity and evidence pages are yours to write: the app never changes their text after creating them. See Evidence, reports and audits and Dashboard, tasks and reminders.
What a policy page contains
Each policy template opens with a short note that it was generated from a template and must be reviewed (you can delete the note), then these sections: Purpose, Scope, Roles & Responsibilities, Policy Statements, Exceptions, Enforcement, Related Documents, and an effective date. Your company name and security contact are filled in once, when the page is created.
What an activity page contains
Each activity page has an Objective, Cadence, Controls supported, Procedure and Evidence to keep, followed by its evidence pages. Each evidence page states its period and due date, and has a checklist of the evidence to collect with a section to fill in for each item.
Policies
SOC 2 provisions 24 policies. Every policy defaults to a 12-month (annual) review. "Acknowledgement" shows whether employees are asked to acknowledge each approved version of the policy. See Policies and approvals and Policy acknowledgements.
| Policy | Categories | Default review | Acknowledgement | Criteria |
|---|---|---|---|---|
| Information Security Policy | Security | 12 months | Yes | CC1.1, CC2.1, CC5.3 |
| Acceptable Use Policy | Security | 12 months | Yes | CC1.1, CC2.2 |
| Code of Conduct | Security | 12 months | Yes | CC1.1 |
| Information Security Roles & Responsibilities | Security | 12 months | No | CC1.2, CC1.3 |
| Access Control Policy | Security | 12 months | Yes | CC6.1, CC6.2, CC6.3 |
| Asset Management Policy | Security | 12 months | Yes | CC6.1 |
| Data Classification & Handling Policy | Security, Confidentiality | 12 months | Yes | CC6.1, C1.1 |
| Data Retention & Disposal Policy | Security, Confidentiality | 12 months | No | C1.2, CC6.5 |
| Encryption & Key Management Policy | Security | 12 months | No | CC6.1, CC6.7 |
| Human Resources Security Policy | Security | 12 months | No | CC1.4, CC1.5 |
| Risk Management Policy | Security | 12 months | No | CC3.1, CC3.2, CC3.3, CC3.4 |
| Vendor & Third-Party Management Policy | Security | 12 months | No | CC9.2 |
| Change Management Policy | Security | 12 months | Yes | CC8.1 |
| Secure Software Development Policy | Security | 12 months | Yes | CC8.1 |
| Vulnerability Management Policy | Security | 12 months | No | CC7.1 |
| Logging & Monitoring Policy | Security | 12 months | No | CC7.2, CC7.3 |
| Incident Response Plan | Security | 12 months | Yes | CC7.3, CC7.4, CC7.5 |
| Network Security Policy | Security | 12 months | No | CC6.6 |
| Physical & Environmental Security Policy | Security | 12 months | Yes | CC6.4 |
| Business Continuity & Disaster Recovery Plan | Security, Availability | 12 months | No | A1.2, A1.3, CC9.1 |
| Backup Policy | Availability | 12 months | No | A1.2 |
| Capacity & Performance Management Policy | Availability | 12 months | No | A1.1 |
| Data Processing Integrity Policy | Processing Integrity | 12 months | No | PI1.1, PI1.2, PI1.3, PI1.4, PI1.5 |
| Privacy Policy | Privacy | 12 months | Yes | P1.1 to P8.1 (all 18 privacy criteria) |
The Privacy Policy is an internal policy for the people who work for your company. It is not the privacy notice you publish to customers.
Recurring activities
SOC 2 provisions 15 recurring activities. Each period's evidence is due on the last day of the period, and periods follow your fiscal year. The evidence page for a period opens a set number of days before it is due (the notice period): 14 days by default for every activity, adjustable per activity from 0 to 90 days. Every activity's evidence is submitted for approval. See Recurring activities.
| Activity | Cadence | Notice | Category | What's done | Evidence checklist |
|---|---|---|---|---|---|
| User Access Review | Quarterly | 14 days | Security | Confirm only the right people have the right access to important systems, and remove what's no longer needed. | Systems in scope; reviewer; users removed or changed; export attached |
| Risk Assessment | Annual | 14 days | Security | Identify and rate the risks to your security commitments and decide how each is treated. | Risk register snapshot; new risks; treatment decisions |
| Annual Policy Review | Annual | 14 days | Security | Confirm every policy still matches how the company works, has the right owner, and was re-approved where it changed. | A list of the policies with their approval dates, generated by the app on the evidence page |
| Security Awareness Training | Annual | 14 days | Security | Train everyone to spot and report threats and to know their policy responsibilities, and record completion. | Training material; completion roster |
| Vendor Risk Review | Annual | 14 days | Security | Confirm you know which vendors you rely on and that each one's security is still acceptable. | Vendor list; SOC reports collected; risk ratings |
| Penetration Test | Annual | 14 days | Security | Have a qualified, independent tester attack your product and infrastructure, and fix what they find. | Report; findings; remediation tickets |
| Vulnerability Scan Review | Monthly | 14 days | Security | Review automated scan results, decide on each significant finding, and track fixes to the agreed timeframes. | Scan results; triage decisions |
| Incident Response Tabletop | Annual | 14 days | Security | Walk through a realistic incident scenario to practise the plan and find its gaps. | Scenario; participants; lessons learned |
| Business Continuity / DR Test | Annual | 14 days | Availability | Prove critical services can be recovered within the committed recovery time and recovery point targets. | Test plan; RTO/RPO achieved; issues |
| Backup Restore Test | Quarterly | 14 days | Availability | Show that backups can actually be restored and that the restored data is complete and usable. | Restore performed; integrity verified |
| Asset Inventory Review | Semi-annual | 14 days | Security | Keep an accurate, owned inventory of the assets that hold or process company and customer data. | Inventory export; changes |
| Network / Firewall Config Review | Semi-annual | 14 days | Security | Check that firewall rules and other network access controls allow only the traffic the business needs. | Rule review; changes made |
| Management Security Review Meeting | Quarterly | 14 days | Security | Give leadership a regular, recorded review of the security program's risks, incidents and control gaps. | Agenda; attendees; decisions |
| Org Chart & Roles Review | Annual | 14 days | Security | Keep the organizational structure, reporting lines and security responsibilities defined and current. | Current org chart; role changes |
| Performance Reviews Completed | Annual | 14 days | Security | Show that every employee's performance, including their security responsibilities, is evaluated. | Confirmation; completion % |
The criteria each activity supports are listed under Control mappings.
Note: event-driven controls, such as background checks on hire and onboarding or offboarding checklists, are not recurring activities and are not provisioned. Acknowledgement of policies by new starters is handled by policy acknowledgements.
Control mappings
Every policy and activity is mapped to one or more SOC 2 criteria. The tables below list each criterion with the policies and activities mapped to it, grouped by category. A criterion appears in your controls matrix only if its category is selected. Four Security criteria (CC2.3, CC5.1, CC5.2 and CC6.8) have nothing mapped to them by default, so the controls matrix shows them as gaps: plan with your auditor how you will evidence them.
Tip: the generated Controls Matrix — SOC 2 page in your compliance space shows this mapping live: for each criterion it lists the mapped policies and activities with their current status, links to their pages, and a covered, attention or gap roll-up. See Evidence, reports and audits.
Security (Common Criteria)
| Criterion | Description (paraphrased) | Policies | Activities |
|---|---|---|---|
| CC1.1 | Commitment to integrity and ethical values | Information Security Policy; Acceptable Use Policy; Code of Conduct | None |
| CC1.2 | Independent oversight by the board or leadership | Information Security Roles & Responsibilities | Management Security Review Meeting |
| CC1.3 | Structures, reporting lines and authority | Information Security Roles & Responsibilities | Org Chart & Roles Review |
| CC1.4 | Attracting, developing and retaining competent people | Human Resources Security Policy | Security Awareness Training; Performance Reviews Completed |
| CC1.5 | Accountability for control responsibilities | Human Resources Security Policy | Performance Reviews Completed |
| CC2.1 | Relevant, quality information for internal control | Information Security Policy | None |
| CC2.2 | Internal communication of objectives and responsibilities | Acceptable Use Policy | Security Awareness Training; Management Security Review Meeting |
| CC2.3 | Communication with external parties | None | None |
| CC3.1 | Objectives clear enough to assess risk | Risk Management Policy | Risk Assessment |
| CC3.2 | Identifying and analysing risks | Risk Management Policy | Risk Assessment |
| CC3.3 | Considering the potential for fraud | Risk Management Policy | Risk Assessment |
| CC3.4 | Assessing significant changes | Risk Management Policy | Risk Assessment |
| CC4.1 | Ongoing and separate evaluations of controls | None | Penetration Test |
| CC4.2 | Communicating control deficiencies | None | Management Security Review Meeting |
| CC5.1 | Control activities that reduce risk | None | None |
| CC5.2 | General controls over technology | None | None |
| CC5.3 | Policies and procedures that put controls in place | Information Security Policy | Annual Policy Review |
| CC6.1 | Logical access security | Access Control Policy; Asset Management Policy; Data Classification & Handling Policy; Encryption & Key Management Policy | Asset Inventory Review |
| CC6.2 | Registering and authorizing users | Access Control Policy | User Access Review |
| CC6.3 | Role-based access and least privilege | Access Control Policy | User Access Review |
| CC6.4 | Physical access to facilities and assets | Physical & Environmental Security Policy | None |
| CC6.5 | Disposal of assets and data | Data Retention & Disposal Policy | None |
| CC6.6 | Protection against threats from outside the system boundary | Network Security Policy | Network / Firewall Config Review |
| CC6.7 | Protecting data in transmission and movement | Encryption & Key Management Policy | None |
| CC6.8 | Preventing and detecting malicious software | None | None |
| CC7.1 | Detecting vulnerabilities and configuration changes | Vulnerability Management Policy | Penetration Test; Vulnerability Scan Review |
| CC7.2 | Monitoring for anomalies and security events | Logging & Monitoring Policy | None |
| CC7.3 | Evaluating security events | Logging & Monitoring Policy; Incident Response Plan | None |
| CC7.4 | Responding to security incidents | Incident Response Plan | Incident Response Tabletop |
| CC7.5 | Recovering from security incidents | Incident Response Plan | Incident Response Tabletop |
| CC8.1 | Managing changes to systems | Change Management Policy; Secure Software Development Policy | None |
| CC9.1 | Mitigating business disruption risk | Business Continuity & Disaster Recovery Plan | None |
| CC9.2 | Managing vendor and business partner risk | Vendor & Third-Party Management Policy | Vendor Risk Review |
Availability
| Criterion | Description (paraphrased) | Policies | Activities |
|---|---|---|---|
| A1.1 | Managing capacity | Capacity & Performance Management Policy | None |
| A1.2 | Environmental protection, backup and recovery infrastructure | Business Continuity & Disaster Recovery Plan; Backup Policy | Backup Restore Test |
| A1.3 | Testing recovery plans | Business Continuity & Disaster Recovery Plan | Business Continuity / DR Test |
Confidentiality
| Criterion | Description (paraphrased) | Policies | Activities |
|---|---|---|---|
| C1.1 | Identifying and protecting confidential information | Data Classification & Handling Policy | None |
| C1.2 | Disposing of confidential information | Data Retention & Disposal Policy | None |
Processing Integrity
| Criterion | Description (paraphrased) | Policies | Activities |
|---|---|---|---|
| PI1.1 | Processing specifications and definitions | Data Processing Integrity Policy | None |
| PI1.2 | Complete and accurate inputs | Data Processing Integrity Policy | None |
| PI1.3 | Complete and accurate processing | Data Processing Integrity Policy | None |
| PI1.4 | Complete and accurate outputs | Data Processing Integrity Policy | None |
| PI1.5 | Storing inputs, work in progress and outputs | Data Processing Integrity Policy | None |
Privacy
All 18 privacy criteria are mapped to the Privacy Policy. No recurring activity is mapped to them.
| Criterion | Description (paraphrased) | Policies |
|---|---|---|
| P1.1 | Privacy notice | Privacy Policy |
| P2.1 | Choice and consent | Privacy Policy |
| P3.1 | Collecting only what the objectives need | Privacy Policy |
| P3.2 | Explicit consent where required | Privacy Policy |
| P4.1 | Using personal information only for its purposes | Privacy Policy |
| P4.2 | Retaining personal information | Privacy Policy |
| P4.3 | Disposing of personal information | Privacy Policy |
| P5.1 | Giving data subjects access to their information | Privacy Policy |
| P5.2 | Correcting personal information | Privacy Policy |
| P6.1 | Disclosing to third parties with consent | Privacy Policy |
| P6.2 | Records of authorized disclosures | Privacy Policy |
| P6.3 | Records of unauthorized disclosures | Privacy Policy |
| P6.4 | Privacy commitments from third parties | Privacy Policy |
| P6.5 | Third parties reporting unauthorized disclosures | Privacy Policy |
| P6.6 | Notifying affected parties of breaches | Privacy Policy |
| P6.7 | Accounting of disclosures to data subjects | Privacy Policy |
| P7.1 | Accurate, complete and relevant personal information | Privacy Policy |
| P8.1 | Handling privacy inquiries, complaints and disputes | Privacy Policy |
Framework versions
This reference describes SOC 2 framework version 1. Later releases of the app may extend the framework with new policies, activities, criteria mappings or pages. A new version never removes or renames anything, and nothing changes on your site until a Compliance Admin applies it.
- When an update is available, Settings → Frameworks & pages shows what it adds: a summary of the changes, the pages it will create and any new criteria in the controls matrix.
- Choosing Apply update creates the new pages. Existing pages, including everything your team has edited, are never changed.
- Improved template text in a new version only applies to pages created from then on. Pages you already have stay as they are.
See Administration for the details.