There are five trust services criteria and only one is compulsory. Security is in scope for every SOC 2, while Availability, Confidentiality, Processing Integrity and Privacy are elected. Each one you add brings its own controls and its own evidence to gather, across the very same window.
A tick is not evidence.
Every checklist lists policies. Fieldwork samples evidence. This one pairs each criterion with the artefact that answers it.
Our promise
“A control you cannot evidence is a claim.”
Every line is read against the artefact behind it — the dated record fieldwork will ask to sample, not the policy that says you do it. The fee is fixed at $12,500, and nothing is charged until you approve it.
Request this readiness scanThe checklist, in three chapters
There is no official control list. The AICPA publishes criteria rather than a numbered catalogue, so a checklist promising sixty controls is describing a vendor product. What is fixed is the five criteria, and what each one asks you to show is true about your own system.
Our job is the read before the audit. We take each criterion you have elected, find the control you actually run against it, name the dated artefact that answers it, and mark every line where no artefact exists. We issue no opinion and sell no software of our own, so no gap here is there to sell a tool.
Five criteria. Only one is compulsory.
The opinion is signed by a licensed CPA firm. The read before it is ours.
- Access control - reviewed, dated, and with a reviewer
- MFA and encryption - read from the running system
- Vulnerabilities - scanned, triaged and closed out
- Incident response - a plan, and one rehearsal of it
- Availability - monitoring, and a restore that actually ran
- Training and vendors - completions, and a reviewed list
- Confidentiality - classification, retention and disposal
- Privacy - a rights route, and the consent trail behind it
The list is easy. The evidence is not.
Security, then what you elect
Security is always in scope. Availability, Confidentiality, Processing Integrity and Privacy are elected, and each one you add brings its own criteria, its own controls and its own evidence to collect across the same window. Elect what a buyer has asked for in writing, not what merely looks thorough.
Who actually tests the list
A licensed CPA firm tests the controls and signs the opinion. They decide what satisfies a criterion for your own system - not a vendor checklist, and certainly not us. We are not a CPA firm and we issue no report of any kind. What we can do is read you the way they will, while changing things is still cheap.
A tick is not evidence
Fieldwork does not test whether a policy exists. It tests whether a control actually operated, and asks for the dated record that proves it. Teams tick every line of a published checklist and yet still fail a Type II, because nothing in that year produced the artefact the auditor then asks to sample.
“We have all the policies. We should pass.”
Fieldwork samples records, not policies.
It is the most common finding we write up.
- Who it is for
- SaaS & platform vendors
- Startups selling upmarket
- Security & GRC leads
- Engineering leads
- Founders answering an RFP
Two firms can quote the same report and differ several times over, because they are quoting different scopes, windows and testing depths.
A Type II covers a period you choose. Nobody bills you for the window, and it is the line that decides when you can answer the buyer.
The report expires with its period. Budget SOC 2 as a subscription rather than a project, or year two arrives as a surprise.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your readiness check
Four phases, and the last one is elapsed time.
The middle two are work you control. The last one is elapsed time, and no amount of effort makes a window pass faster than it passes.
-
Scoped
Weeks 1-2The boundary drawn, the criteria elected, a gap assessment run and an owner put against each area.
-
Written
Weeks 2-6Policies drafted and approved - access control, change management, incident response, vendor risk.
-
Implemented
Weeks 6-14Controls actually running: access managed, logging and monitoring on, staff trained, tools deployed.
-
Evidenced
Then the windowEvidence collected right across the period, and then fieldwork samples it. A Type I stops before this part.
Teams tick the list and stop there. The thing fieldwork samples is not on any checklist — it is the dated record showing the control operated, and it cannot be created after the window has run.
What the criteria ask, what answers them
12 things to settle, and the artefact that answers each one. Paired, so every claim on this page can be checked against the requirement beside it.
- Access control and joiners Security - always in scope
- A dated access review with the reviewer named, and leaver records that match your HR dates rather than your intentions.
- Multi-factor authentication Security - and the first thing sampled
- Configuration proof for every system in the boundary, plus the exceptions list and who approved each one.
- Encryption in transit and at rest Security, and Confidentiality where elected
- Settings read out of the running system rather than a policy sentence asserting that encryption is enabled.
- Vulnerability management Security - scanning, triage and closure
- Scan output with dates, the triage decision on each finding, and evidence that the fix or the acceptance happened.
- Incident response Security - the plan and the rehearsal
- The plan, plus one real or tabletop incident with timestamps, decisions and who was told - a plan alone samples badly.
- Security awareness training Security - completion, not availability
- Completion records per person per period, which is the artefact, rather than a link to a course nobody finished.
- Vendor and subservice risk Security - and it reaches your own suppliers
- The vendor list, what each one touches, the review you performed, and the carve-out or inclusive decision recorded.
- Availability and recovery Availability - only if you elect it
- Monitoring and alerting proof, plus a restoration test that actually restored something, with the date it ran.
- Backup restoration testing Availability - the test, not the backup
- Evidence that a restore was performed and verified, because a backup nobody has restored is an untested assumption.
- Change management Processing Integrity, and Security throughout
- A sample of real changes showing review, approval and deployment - traceable from ticket to release.
- Data classification and retention Confidentiality - and disposal counts
- The classification scheme in use, where each class lives, and proof that disposal happens on the stated schedule.
- Data subject rights and consent Privacy - the least-elected criterion
- A working request route, response records inside your stated window, and the consent trail behind each use.
Your control set, independently read
From Security alone to all five criteria.
-
Elect
Security is in scope already. Which of the other four your buyer actually asked for.
-
Check
Every control area read against what you run, and against the evidence it produces.
-
Close and sign off
You see the draft first. Then the gap list, the evidence index and the shortlist - dated.
Why teams ask iDharma to read the list with them
We sell no software
No platform to license and no seats to grow, so we have no reason to call your spreadsheet a gap.
We do not issue the SOC 2
A licensed CPA firm signs that opinion. We read you before it, and we say so on every page.
Evidence, not ticks
Every line is checked against the dated artefact behind it, which is what fieldwork samples.
One fixed fee, published
The readiness price is on this page and in the checkout, and no finding we make changes it.
Four marks, struck on every readiness report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Readiness report, by criterion
The whole checklist answered in one document: which criteria you elected and why, every control area underneath each of them, what you run against it today, which dated artefact answers it, where that artefact does not exist yet, and what closing each remaining gap takes in money and in hours before fieldwork begins.
Criteria checklist workbook
Every control area as a row you can work through, with the elected criteria marked and an owner against each line.
Evidence index
What artefact answers each criterion, where it lives, who produces it and how often - the part a checklist leaves out.
Policy gap list
Which policies the criteria actually require, which of yours exist, and which describe a process nobody follows now.
Scope memo
What sits inside the boundary, which criteria were elected and why, and what was deliberately left out of both.
Remediation shortlist
What to fix before fieldwork and what can wait, ranked by what the opinion is at risk on rather than what is quickest.
Type I or Type II memo
Which report your buyer actually asked for, what each one tests, and what the window costs you in evidence hours.
Real numbers, upfront.
- Scope
- Set by the criteria you elect
- Input
- Your controls, policies, evidence
- Re-read
- Annually, or on a scope change - a new system, a new criterion, a new buyer asking.
The scope is fixed before the meter starts, so the fee is flat - and nothing is charged until you approve it.
Request your scan- Independent readiness report, costed
- Pipeline trace, transform by transform
- Vendor-clause review included
- A dated evidence trail you keep
Four things fieldwork asks you to produce
Good faith is not a document. Each of these is either in your hand on the day somebody asks, or it is not.
The policy,
approved
Written, dated and approved by somebody with the authority to approve it. The weakest kind of evidence there is, and the only kind most checklists collect.
The control,
running
The setting read out of the live system rather than the policy sentence describing it. Configuration is what gets sampled when a policy claims something.
The record,
dated
Proof the control operated on a date - the review performed, the ticket approved, the restore tested. This is the artefact a Type II is actually built from.
The exception,
owned
Where a control did not operate, the record saying so, who accepted it and until when. Exceptions handled openly cost far less than exceptions discovered.
Four artefacts, and only the first one is a document.
Plain answers
Scope, timing, and the cost of getting it wrong. Answered straight.
Request your scanHow many controls are in SOC 2?
There is no official number. The AICPA publishes criteria, not a numbered control catalogue - so any "60 controls" list is a vendor's own taxonomy. What is fixed is the five criteria, and Security is the only one always in scope.
Do we need all five trust services criteria?
No. Security is always in scope; Availability, Confidentiality, Processing Integrity and Privacy are elected. Each one you add brings its own controls and its own evidence across the same window, so elect what a buyer asked for in writing.
Type I or Type II - which do we need?
Most enterprise buyers mean Type II. A Type I tests design at a point in time; a Type II tests whether controls operated across a period. Paying for the wrong one is the most common waste on a first SOC 2, and one email settles it.
How long does it take to be audit-ready?
Commonly three to four months of work before the window opens - scope and gap read, policies, then controls actually running. The window itself is extra, and a Type II cannot be shortened by working harder inside it.
What evidence does the auditor actually ask for?
Dated artefacts, sampled. Access reviews with a reviewer and a date, tickets showing approval, scan output with the triage decision, training completion per person, a restore that actually ran. Not the policy that says you do these things.
Request your readiness review
Tell us what you generate and where it goes, and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which systems sit inside the boundary
- Where that content is published, and who gets to see it
- Any documentation - policies, prior reports
- Whether you host the model, buy it, or fine-tune one
- A published asset or two, exactly as your readers get them
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- AICPA Trust Services Criteria (2017, rev. 2022)
- AICPA SSAE No. 18, AT-C section 205
- Criteria
- TSC 2017, rev. 2022
- Last read
- 14 September 2026
What it means
- General information about what the criteria ask — not legal or accounting advice, and no professional relationship arises from reading it. It determines nothing about your own systems.
- Where a scope question is arguable, our reports say so rather than the convenient one.
Scope & limitation
- Control areas are our reading of the criteria, not an AICPA mapping.
- The AICPA publishes criteria, not a numbered control list - see above.
- Do not rest a binding decision on it; engage qualified counsel.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.