SOC 2 Compliance

SOC 2 isn't one framework. It's eight.
We've decomposed all of them.

AICPA TSC, DC200, COSO, CIS Controls, CSA CCM, COBIT, ISAE 3402, ISAE 3000 — 924 obligations across the complete SOC 2 ecosystem. AuditDSS maps them all and tells you exactly where you stand.

924

SOC 2 obligations

8

Frameworks

320+

Regulatory frameworks

146,445+

Scored obligations

Most companies treat SOC 2 as a checklist. It's actually an ecosystem.

Every compliance team knows they need SOC 2. But most treat it as a single certification with a single set of controls. In reality, SOC 2 is built on an ecosystem of 8 interconnected frameworks. The Trust Services Criteria (TSC) define WHAT must be controlled — but they're built on COSO's 17 principles. DC200 defines WHAT must be described in your system description. CIS Controls and CSA CCM tell you HOW to implement security controls. COBIT provides the IT governance structure. And ISAE 3402/3000 define what your auditor actually examines.

Most companies discover these connections when their auditor asks a question they can't answer. AuditDSS maps every connection before that happens.

That's what AuditDSS does.

The complete SOC 2 ecosystem — decomposed

924 obligations across 8 frameworks, scored and ready. AuditDSS is the only platform that decomposes ALL of them and shows how they connect.

Updated March 2026 — new frameworks added regularly

Tier 3 Assurance Standards — What Auditors Examine

From regulation to compliance in four steps

1

Assess

Score your organisation against all 58 TSC criteria. Gap analysis tells you exactly what's missing — not just 'you need better access controls', but which specific CC criteria you fail and why.

2

Describe

Generate your system description using all 27 DC200 criteria. AuditDSS ensures your description covers infrastructure, software, people, procedures, data, subservice organisations, and complementary user entity controls.

3

Implement

The embedding layer surfaces relevant CIS Controls (153 safeguards) and CSA CCM controls (197 objectives) for every TSC gap. Not generic recommendations — prescriptive controls mapped to your specific criteria failures.

4

Prove

Map your existing evidence to the 56 ISAE 3402 obligations your auditor will examine. See exactly which controls have evidence and which gaps remain before your Type 2 examination window opens.

Your existing security data is compliance evidence — we connect the dots

Security Controls & SIEM

Firewall configs, SIEM logs, vulnerability scan results, access control records, and encryption settings. AuditDSS maps your security evidence to specific TSC criteria (CC6, CC7, CC8), CIS Controls safeguards, and CSA CCM control objectives simultaneously.

Policies & Procedures

Information security policies, acceptable use policies, incident response plans, business continuity plans, and change management procedures. Direct evidence for COSO principles, COBIT governance objectives, and TSC Common Criteria CC1-CC5.

HR & Governance

Background check records, training completion, org charts, board minutes, risk committee documentation, and code of conduct acknowledgments. Maps to COSO control environment (CC1), TSC criteria, and COBIT governance domain (EDM).

Vendor & Cloud

Vendor risk assessments, SOC 2 reports from subservice organisations, cloud configuration reviews, and SLA documentation. Evidence for DC200 criteria DC6 (complementary user entity controls), DC7 (subservice organisations), and CSA CCM supply chain controls.

You don't need to build a separate evidence library for each framework. You need one platform that maps your existing evidence to obligations across TSC, COSO, CIS, CSA CCM, COBIT, and ISAE simultaneously. That's what AuditDSS does — and it's why auditors love working with our clients.

Compliance isn't just a cost — it's a competitive advantage

Most compliance platforms tell you what you must do to avoid penalties. AuditDSS also tells you what you gain by complying.

Audit readiness

Pre-mapped evidence across all ${totalSoc2Obligations} obligations. Know your gaps before the auditor arrives.

Faster Type 2

Reduce SOC 2 preparation from 6-12 months to weeks by knowing exactly what's needed from day one.

Cross-framework efficiency

One control can satisfy TSC, CIS, CSA CCM, and COBIT simultaneously. AuditDSS shows every overlap.

Enterprise sales

SOC 2 is table stakes for enterprise deals. Certified companies close deals 40% faster.

Customer trust

Demonstrate comprehensive compliance that goes beyond checkbox SOC 2 — show the full ecosystem.

Cost reduction

Stop paying consultants to map frameworks manually. AuditDSS has already decomposed all ${totalSoc2Obligations} obligations.

Built for everyone in the SOC 2 compliance chain

SaaS & Cloud Companies

The most common SOC 2 candidates. Map your cloud infrastructure against TSC criteria and CSA CCM controls. Generate your DC200 system description. Know your audit readiness score before engaging an auditor.

Compliance & InfoSec Teams

Manage the full SOC 2 program from one workspace. See how a single control satisfies multiple criteria across TSC, CIS, and CSA CCM. Track evidence collection against ISAE 3402 requirements.

SOC 2 Auditors & CPA Firms

Use Advisor Mode to assess clients across the complete SOC 2 ecosystem. The obligation-level decomposition means no criteria gets missed. Generate audit-ready workpapers with evidence mapping.

Startups Preparing for SOC 2

Don't know where to start? AuditDSS shows you the 58 TSC criteria, prioritised by risk, with specific CIS Controls telling you exactly what to implement. From zero to audit-ready, structured.

Enterprise compliance intelligence, built for SOC 2

Regulation Finder

Answer a few questions, discover every regulation that applies to your business

Obligation-Level Decomposition

Not just 'you need SOC 2' but 924 specific obligations across 8 frameworks, scored by risk

Gap Analysis & Risk Scoring

See exactly where you're compliant and where you're exposed

Policy & Procedure Generation

Deterministic document generation for system descriptions, security policies, and procedures. Every clause traced to TSC criteria and COSO principles.

Dual Workspace Mode

Company Mode for your own compliance. Advisor Mode for consultants managing multiple clients.

Ready to see the full SOC 2 ecosystem?

Discover which frameworks apply to your business in minutes — or book a walkthrough to see AuditDSS in action.

Building GRC, security, or audit technology? AuditDSS provides the compliance intelligence layer for SIEM, vulnerability management, policy management, and audit workflow platforms. Contact us about integration partnerships