Frameworks · Global standards
SOC 2 compliance, run as a living system
SOC 2 is the AICPA's attestation framework for service organisations, reporting against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
Who it applies to
Service organisations whose customers demand independent assurance over security and related criteria, most commonly SaaS and technology providers selling to enterprises.
What it demands
Common criteria
Control environment, communication, risk assessment, monitoring and change management.
Optional criteria
Availability, processing integrity, confidentiality and privacy as scoped.
Evidence over the period
Type II reports examine operating effectiveness across the review period.
Readiness & attestation
Readiness assessment followed by the attestation engagement.
How Compli-Once runs it
- 1
Trust Services Criteria modelled and crosswalked to ISO 27001, so evidence is collected once.
- 2
Evidence expiry tracking keeps Type II periods clean, lapses raise tasks before they become exceptions.
- 3
The attestation runs as an audit engagement with scoped evidence requests through the auditor portal.
What you already satisfy
SOC 2 overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
Does Compli-Once support SOC 2 Type II?
Yes. Controls carry evidence continuously across the review period, expiry is tracked with pre-lapse renewal tasks, and the attestation runs as an engagement with scoped evidence requests.
How does SOC 2 overlap with ISO 27001?
Heavily. The crosswalk maps the criteria to Annex A controls, so most evidence serves both. Adopting one after the other is measured in days, not months.
Should a pure-US software company pick Compli-Once for SOC 2?
If SOC 2 for US customers is your only obligation, a certification automation platform is a strong choice and our comparison pages say so. Compli-Once earns its place when regulatory mandates join the list.
Can our auditor work in the platform?
Yes. Auditors get scoped portal access to evidence requests at no cost to them, with every access recorded in the activity log.
