User guide

SOC 2 content reference

For Compliance Admins and auditors: exactly what the app provisions for SOC 2, from the Trust Services Categories and page tree to every policy, recurring activity and criteria mapping.

  • Compliance Admins
  • Auditors

About this content

The SOC 2 framework in Compliance in a Box is built on the 2017 Trust Services Criteria, with the 2022 revised points of focus. When you generate the compliance pages, the app creates a policy page for each policy and an activity page for each recurring activity in the categories you chose, and maps each of them to SOC 2 criteria. This chapter lists all of it, as shipped in framework version 1.

The criteria descriptions on this page are short labels in our own words, not the AICPA's criteria text. Use the criterion IDs to look up the official wording.

Important: the policy and activity templates are a starting point, not legal or audit advice. Review each one and adapt it to how your company actually works before you approve it. The criteria mappings are an initial, indicative mapping: have your auditor review them. Using the app does not by itself make your company SOC 2 compliant, and it does not replace an independent auditor. SOC 2 and the Trust Services Criteria are AICPA frameworks; Compliance in a Box is not affiliated with or endorsed by the AICPA.

Trust Services Categories

When you generate the compliance pages (Settings → Frameworks & pages), you choose which Trust Services Categories your SOC 2 report covers. Security is always included. The other four are optional. A policy or activity is included when any of its categories is selected, so a page shared by Security and another category is always there.

CategoryRequired?What it adds
Security Always included 20 policies and 13 recurring activities, plus the criteria CC1.1 to CC9.2 in the controls matrix.
Availability Optional 2 policies (Backup Policy; Capacity & Performance Management Policy) and 2 activities (Business Continuity / DR Test; Backup Restore Test), plus criteria A1.1 to A1.3.
Confidentiality Optional No extra pages: its policies (Data Classification & Handling; Data Retention & Disposal) are already part of Security. Adds criteria C1.1 and C1.2 to the controls matrix.
Processing Integrity Optional 1 policy (Data Processing Integrity Policy), plus criteria PI1.1 to PI1.5.
Privacy Optional 1 policy (Privacy Policy), plus criteria P1.1 to P8.1.

With Security only, the app creates 41 pages (8 structure and report pages, 20 policies, 13 activities). With all five categories, it creates 47 (8 structure and report pages, 24 policies, 15 activities).

Note: you can add categories later and generate again; the app only creates the pages that are missing. Categories can't be removed once their pages exist. See Administration.

The page tree

Everything lives in the one compliance space the app manages. The space home page is titled with your company name. The tree below shows every page the app provisions; pages marked "optional category" appear only if that category is selected.

  • <Company> Compliance Program (space home: an overview of the program and how to use the space)
    • Policies
      • One page per policy in scope (see Policies)
    • Recurring Activities
      • One page per activity, titled with its cadence, for example "User Access Review (Quarterly)"
        • One evidence page per period, created ahead of its due date, for example "User Access Review — 2026 Q3" (or "— FY2027 Q1" when your fiscal year doesn't start in January)
    • Controls Matrix — SOC 2 (generated)
    • Evidence & Reports
      • Policy Approval Log (generated), with one page per year, for example "Policy Approval Log — 2026"
      • Policy Acknowledgement Report (generated), with one page per year
      • Activity Completion Report (generated), with one page per year
      • Audit Log (generated; created by the first report refresh), with one page per month, for example "Audit Log — September 2026"
      • Weekly compliance summary (generated; only when the weekly summary reminder is in use)
    • Compliance Tasks (only when reminders are in use), with one private task page per person

Generated pages are rebuilt by the app from its records, daily and on demand, so edits to them are overwritten. Report pages are restricted to Compliance Admins (and the Auditors group, if you set one). Policy, activity and evidence pages are yours to write: the app never changes their text after creating them. See Evidence, reports and audits and Dashboard, tasks and reminders.

What a policy page contains

Each policy template opens with a short note that it was generated from a template and must be reviewed (you can delete the note), then these sections: Purpose, Scope, Roles & Responsibilities, Policy Statements, Exceptions, Enforcement, Related Documents, and an effective date. Your company name and security contact are filled in once, when the page is created.

What an activity page contains

Each activity page has an Objective, Cadence, Controls supported, Procedure and Evidence to keep, followed by its evidence pages. Each evidence page states its period and due date, and has a checklist of the evidence to collect with a section to fill in for each item.

Policies

SOC 2 provisions 24 policies. Every policy defaults to a 12-month (annual) review. "Acknowledgement" shows whether employees are asked to acknowledge each approved version of the policy. See Policies and approvals and Policy acknowledgements.

PolicyCategoriesDefault reviewAcknowledgementCriteria
Information Security PolicySecurity12 monthsYesCC1.1, CC2.1, CC5.3
Acceptable Use PolicySecurity12 monthsYesCC1.1, CC2.2
Code of ConductSecurity12 monthsYesCC1.1
Information Security Roles & ResponsibilitiesSecurity12 monthsNoCC1.2, CC1.3
Access Control PolicySecurity12 monthsYesCC6.1, CC6.2, CC6.3
Asset Management PolicySecurity12 monthsYesCC6.1
Data Classification & Handling PolicySecurity, Confidentiality12 monthsYesCC6.1, C1.1
Data Retention & Disposal PolicySecurity, Confidentiality12 monthsNoC1.2, CC6.5
Encryption & Key Management PolicySecurity12 monthsNoCC6.1, CC6.7
Human Resources Security PolicySecurity12 monthsNoCC1.4, CC1.5
Risk Management PolicySecurity12 monthsNoCC3.1, CC3.2, CC3.3, CC3.4
Vendor & Third-Party Management PolicySecurity12 monthsNoCC9.2
Change Management PolicySecurity12 monthsYesCC8.1
Secure Software Development PolicySecurity12 monthsYesCC8.1
Vulnerability Management PolicySecurity12 monthsNoCC7.1
Logging & Monitoring PolicySecurity12 monthsNoCC7.2, CC7.3
Incident Response PlanSecurity12 monthsYesCC7.3, CC7.4, CC7.5
Network Security PolicySecurity12 monthsNoCC6.6
Physical & Environmental Security PolicySecurity12 monthsYesCC6.4
Business Continuity & Disaster Recovery PlanSecurity, Availability12 monthsNoA1.2, A1.3, CC9.1
Backup PolicyAvailability12 monthsNoA1.2
Capacity & Performance Management PolicyAvailability12 monthsNoA1.1
Data Processing Integrity PolicyProcessing Integrity12 monthsNoPI1.1, PI1.2, PI1.3, PI1.4, PI1.5
Privacy PolicyPrivacy12 monthsYesP1.1 to P8.1 (all 18 privacy criteria)

The Privacy Policy is an internal policy for the people who work for your company. It is not the privacy notice you publish to customers.

Recurring activities

SOC 2 provisions 15 recurring activities. Each period's evidence is due on the last day of the period, and periods follow your fiscal year. The evidence page for a period opens a set number of days before it is due (the notice period): 14 days by default for every activity, adjustable per activity from 0 to 90 days. Every activity's evidence is submitted for approval. See Recurring activities.

ActivityCadenceNoticeCategoryWhat's doneEvidence checklist
User Access ReviewQuarterly14 daysSecurityConfirm only the right people have the right access to important systems, and remove what's no longer needed.Systems in scope; reviewer; users removed or changed; export attached
Risk AssessmentAnnual14 daysSecurityIdentify and rate the risks to your security commitments and decide how each is treated.Risk register snapshot; new risks; treatment decisions
Annual Policy ReviewAnnual14 daysSecurityConfirm every policy still matches how the company works, has the right owner, and was re-approved where it changed.A list of the policies with their approval dates, generated by the app on the evidence page
Security Awareness TrainingAnnual14 daysSecurityTrain everyone to spot and report threats and to know their policy responsibilities, and record completion.Training material; completion roster
Vendor Risk ReviewAnnual14 daysSecurityConfirm you know which vendors you rely on and that each one's security is still acceptable.Vendor list; SOC reports collected; risk ratings
Penetration TestAnnual14 daysSecurityHave a qualified, independent tester attack your product and infrastructure, and fix what they find.Report; findings; remediation tickets
Vulnerability Scan ReviewMonthly14 daysSecurityReview automated scan results, decide on each significant finding, and track fixes to the agreed timeframes.Scan results; triage decisions
Incident Response TabletopAnnual14 daysSecurityWalk through a realistic incident scenario to practise the plan and find its gaps.Scenario; participants; lessons learned
Business Continuity / DR TestAnnual14 daysAvailabilityProve critical services can be recovered within the committed recovery time and recovery point targets.Test plan; RTO/RPO achieved; issues
Backup Restore TestQuarterly14 daysAvailabilityShow that backups can actually be restored and that the restored data is complete and usable.Restore performed; integrity verified
Asset Inventory ReviewSemi-annual14 daysSecurityKeep an accurate, owned inventory of the assets that hold or process company and customer data.Inventory export; changes
Network / Firewall Config ReviewSemi-annual14 daysSecurityCheck that firewall rules and other network access controls allow only the traffic the business needs.Rule review; changes made
Management Security Review MeetingQuarterly14 daysSecurityGive leadership a regular, recorded review of the security program's risks, incidents and control gaps.Agenda; attendees; decisions
Org Chart & Roles ReviewAnnual14 daysSecurityKeep the organizational structure, reporting lines and security responsibilities defined and current.Current org chart; role changes
Performance Reviews CompletedAnnual14 daysSecurityShow that every employee's performance, including their security responsibilities, is evaluated.Confirmation; completion %

The criteria each activity supports are listed under Control mappings.

Note: event-driven controls, such as background checks on hire and onboarding or offboarding checklists, are not recurring activities and are not provisioned. Acknowledgement of policies by new starters is handled by policy acknowledgements.

Control mappings

Every policy and activity is mapped to one or more SOC 2 criteria. The tables below list each criterion with the policies and activities mapped to it, grouped by category. A criterion appears in your controls matrix only if its category is selected. Four Security criteria (CC2.3, CC5.1, CC5.2 and CC6.8) have nothing mapped to them by default, so the controls matrix shows them as gaps: plan with your auditor how you will evidence them.

Tip: the generated Controls Matrix — SOC 2 page in your compliance space shows this mapping live: for each criterion it lists the mapped policies and activities with their current status, links to their pages, and a covered, attention or gap roll-up. See Evidence, reports and audits.

Security (Common Criteria)

CriterionDescription (paraphrased)PoliciesActivities
CC1.1Commitment to integrity and ethical valuesInformation Security Policy; Acceptable Use Policy; Code of ConductNone
CC1.2Independent oversight by the board or leadershipInformation Security Roles & ResponsibilitiesManagement Security Review Meeting
CC1.3Structures, reporting lines and authorityInformation Security Roles & ResponsibilitiesOrg Chart & Roles Review
CC1.4Attracting, developing and retaining competent peopleHuman Resources Security PolicySecurity Awareness Training; Performance Reviews Completed
CC1.5Accountability for control responsibilitiesHuman Resources Security PolicyPerformance Reviews Completed
CC2.1Relevant, quality information for internal controlInformation Security PolicyNone
CC2.2Internal communication of objectives and responsibilitiesAcceptable Use PolicySecurity Awareness Training; Management Security Review Meeting
CC2.3Communication with external partiesNoneNone
CC3.1Objectives clear enough to assess riskRisk Management PolicyRisk Assessment
CC3.2Identifying and analysing risksRisk Management PolicyRisk Assessment
CC3.3Considering the potential for fraudRisk Management PolicyRisk Assessment
CC3.4Assessing significant changesRisk Management PolicyRisk Assessment
CC4.1Ongoing and separate evaluations of controlsNonePenetration Test
CC4.2Communicating control deficienciesNoneManagement Security Review Meeting
CC5.1Control activities that reduce riskNoneNone
CC5.2General controls over technologyNoneNone
CC5.3Policies and procedures that put controls in placeInformation Security PolicyAnnual Policy Review
CC6.1Logical access securityAccess Control Policy; Asset Management Policy; Data Classification & Handling Policy; Encryption & Key Management PolicyAsset Inventory Review
CC6.2Registering and authorizing usersAccess Control PolicyUser Access Review
CC6.3Role-based access and least privilegeAccess Control PolicyUser Access Review
CC6.4Physical access to facilities and assetsPhysical & Environmental Security PolicyNone
CC6.5Disposal of assets and dataData Retention & Disposal PolicyNone
CC6.6Protection against threats from outside the system boundaryNetwork Security PolicyNetwork / Firewall Config Review
CC6.7Protecting data in transmission and movementEncryption & Key Management PolicyNone
CC6.8Preventing and detecting malicious softwareNoneNone
CC7.1Detecting vulnerabilities and configuration changesVulnerability Management PolicyPenetration Test; Vulnerability Scan Review
CC7.2Monitoring for anomalies and security eventsLogging & Monitoring PolicyNone
CC7.3Evaluating security eventsLogging & Monitoring Policy; Incident Response PlanNone
CC7.4Responding to security incidentsIncident Response PlanIncident Response Tabletop
CC7.5Recovering from security incidentsIncident Response PlanIncident Response Tabletop
CC8.1Managing changes to systemsChange Management Policy; Secure Software Development PolicyNone
CC9.1Mitigating business disruption riskBusiness Continuity & Disaster Recovery PlanNone
CC9.2Managing vendor and business partner riskVendor & Third-Party Management PolicyVendor Risk Review

Availability

CriterionDescription (paraphrased)PoliciesActivities
A1.1Managing capacityCapacity & Performance Management PolicyNone
A1.2Environmental protection, backup and recovery infrastructureBusiness Continuity & Disaster Recovery Plan; Backup PolicyBackup Restore Test
A1.3Testing recovery plansBusiness Continuity & Disaster Recovery PlanBusiness Continuity / DR Test

Confidentiality

CriterionDescription (paraphrased)PoliciesActivities
C1.1Identifying and protecting confidential informationData Classification & Handling PolicyNone
C1.2Disposing of confidential informationData Retention & Disposal PolicyNone

Processing Integrity

CriterionDescription (paraphrased)PoliciesActivities
PI1.1Processing specifications and definitionsData Processing Integrity PolicyNone
PI1.2Complete and accurate inputsData Processing Integrity PolicyNone
PI1.3Complete and accurate processingData Processing Integrity PolicyNone
PI1.4Complete and accurate outputsData Processing Integrity PolicyNone
PI1.5Storing inputs, work in progress and outputsData Processing Integrity PolicyNone

Privacy

All 18 privacy criteria are mapped to the Privacy Policy. No recurring activity is mapped to them.

CriterionDescription (paraphrased)Policies
P1.1Privacy noticePrivacy Policy
P2.1Choice and consentPrivacy Policy
P3.1Collecting only what the objectives needPrivacy Policy
P3.2Explicit consent where requiredPrivacy Policy
P4.1Using personal information only for its purposesPrivacy Policy
P4.2Retaining personal informationPrivacy Policy
P4.3Disposing of personal informationPrivacy Policy
P5.1Giving data subjects access to their informationPrivacy Policy
P5.2Correcting personal informationPrivacy Policy
P6.1Disclosing to third parties with consentPrivacy Policy
P6.2Records of authorized disclosuresPrivacy Policy
P6.3Records of unauthorized disclosuresPrivacy Policy
P6.4Privacy commitments from third partiesPrivacy Policy
P6.5Third parties reporting unauthorized disclosuresPrivacy Policy
P6.6Notifying affected parties of breachesPrivacy Policy
P6.7Accounting of disclosures to data subjectsPrivacy Policy
P7.1Accurate, complete and relevant personal informationPrivacy Policy
P8.1Handling privacy inquiries, complaints and disputesPrivacy Policy

Framework versions

This reference describes SOC 2 framework version 1. Later releases of the app may extend the framework with new policies, activities, criteria mappings or pages. A new version never removes or renames anything, and nothing changes on your site until a Compliance Admin applies it.

  • When an update is available, Settings → Frameworks & pages shows what it adds: a summary of the changes, the pages it will create and any new criteria in the controls matrix.
  • Choosing Apply update creates the new pages. Existing pages, including everything your team has edited, are never changed.
  • Improved template text in a new version only applies to pages created from then on. Pages you already have stay as they are.

See Administration for the details.