Skip to content

The SOC 2 controls list: what to expect

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · SOC 2

SOC 2 does not hand you a control list — you derive it from the criteria. Here are the families that appear in essentially every report.

Criteria, not a checklist

A frequent surprise: there is no canonical "SOC 2 controls list." The framework defines criteria (the Common Criteria plus optional categories), and you design and document controls that satisfy them. Two companies can pass with different control sets — what matters is that the controls meet the criteria and operate.

The families you will always see

  • Governance: policies, roles, security ownership, and a risk assessment.
  • Access: SSO/MFA, least privilege, periodic access reviews, joiner/mover/leaver.
  • Change: reviewed and approved changes, tested before release.
  • Operations: logging, monitoring, alerting, and backups/DR.
  • Third parties and incidents: vendor management and an incident response plan.

Mostly hygiene, formalised

For an engineering-led company, most of these already exist informally — SSO, code review, monitoring, backups. The SOC 2 work is documenting them as controls and capturing the evidence they run. Resist inventing process the auditor did not ask for; map what you do and close the genuine gaps.

From list to evidence

The hard part is not naming the controls — it is keeping evidence that each one operated across the period. SentinelPanda ships a control set mapped to the criteria, each linked to the evidence it needs, so the list becomes a living program rather than a spreadsheet.

SOC 2 common criteria explained SOC 2 readiness checklist Cross-framework control mapping

Run your compliance program in one workspace.