The SOC 2 controls list: what to expect
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · SOC 2
SOC 2 does not hand you a control list — you derive it from the criteria. Here are the families that appear in essentially every report.
Criteria, not a checklist
A frequent surprise: there is no canonical "SOC 2 controls list." The framework defines criteria (the Common Criteria plus optional categories), and you design and document controls that satisfy them. Two companies can pass with different control sets — what matters is that the controls meet the criteria and operate.
The families you will always see
- Governance: policies, roles, security ownership, and a risk assessment.
- Access: SSO/MFA, least privilege, periodic access reviews, joiner/mover/leaver.
- Change: reviewed and approved changes, tested before release.
- Operations: logging, monitoring, alerting, and backups/DR.
- Third parties and incidents: vendor management and an incident response plan.
Mostly hygiene, formalised
For an engineering-led company, most of these already exist informally — SSO, code review, monitoring, backups. The SOC 2 work is documenting them as controls and capturing the evidence they run. Resist inventing process the auditor did not ask for; map what you do and close the genuine gaps.
From list to evidence
The hard part is not naming the controls — it is keeping evidence that each one operated across the period. SentinelPanda ships a control set mapped to the criteria, each linked to the evidence it needs, so the list becomes a living program rather than a spreadsheet.