Skip to content
SOC 2

SOC 2 compliance software

Prepare for SOC 2 Type I and Type II across the Trust Services Criteria — controls, continuous evidence, a System Description editor, and an auditor-ready review workflow in one workspace.

Free to start, no card · see pricing

9 common criteriaType I + II57-control starter

What SOC 2 requires

SOC 2 (TSC 2017, revised 2022) reports on controls relevant to the Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security category (the nine Common Criteria, CC1 through CC9) is mandatory; the other four are optional and depend on the commitments you make to customers. A Type I report assesses design at a point in time; a Type II report tests operating effectiveness over a 3 to 12 month observation window, which makes continuous evidence, a clear review trail, and a maintained System Description (Section 3) essential.

1 · SCOPE Define the environment 2 · ASSESS Walk every requirement 3 · ATTEST Sign + export the report

Choose your Trust Services Criteria — and your report type

Not every SOC 2 needs every criterion. SentinelPanda starts you on the Security Common Criteria that every report requires, then lets you add Availability, Processing Integrity, Confidentiality, or Privacy based on the commitments you make to customers. The same controls support both a Type I (design at a point in time) and a Type II (operating effectiveness over a 3 to 12 month window), so you can start with Type I and grow into Type II without re-platforming. Unlike a prescriptive standard, SOC 2 has no fixed control count — the AICPA defines the Trust Services Criteria and you define the controls that meet them; SentinelPanda ships a 57-control starter set you tailor to your environment.

The nine Common Criteria, organised the way auditors read them

The Common Criteria are nine categories that every SOC 2 covers: Control Environment (CC1), Communication and Information (CC2), Risk Assessment (CC3), Monitoring Activities (CC4), Control Activities (CC5), Logical and Physical Access (CC6), System Operations (CC7), Change Management (CC8), and Risk Mitigation (CC9). SentinelPanda’s control library is laid out the same way, so when your auditor walks through the report you can show them which controls satisfy each criterion without re-mapping. CC6 (access), CC7 (operations), and CC8 (change management) are where most evidence sits; the workspace surfaces those first and lets you defer the lighter categories until the rest of the program is in place.

A live System Description, not a stale Section 3 Word document

The System Description is the heart of a SOC 2 report — auditors test against what you say you do, so a description that drifts from reality is the fastest way to a qualified opinion. SentinelPanda gives you a versioned System Description editor with sections for company background, principal service commitments, system components, subservice organisations, and the control environment. It pulls live values (active framework set, control counts, connector inventory) so the description stays accurate as the program changes. When the auditor reviews Section 3, you hand over an export, not a document you patched together the week before fieldwork.

Continuous evidence is what makes Type II survivable

Type II is won or lost on whether your controls actually operated for the whole observation period. SentinelPanda’s connectors pull configuration, identity, and vulnerability evidence from AWS, Okta, CrowdStrike, GitHub and more on a schedule, attaching each artifact to the control and timestamp it proves. When the audit arrives, the Auditor Review export hands your CPA firm the workflow history and outcome for every control — no scramble to reconstruct a year of screenshots, no questions about whether a control was operating in week 14.

Subservice organisations and the carve-out method

Every SaaS company relies on subservice organisations — your cloud provider, your identity provider, your email service. SOC 2 lets you treat them with either the inclusive method (you test their controls) or the carve-out method (you rely on their own SOC 2 and document complementary user-entity controls). SentinelPanda tracks each subservice organisation, the controls you depend on them for, the SOC 2 report you reviewed, and the bridge-letter status, so the description and the complementary controls stay aligned. You can also issue your own bridge letter to customers between reports, with a template that pulls the current control inventory automatically.

How SentinelPanda helps

0157-control starter set mapped to the nine Common Criteria (CC1 through CC9) plus the four optional categories
02Supports both Type I (design) and Type II (operating effectiveness)
03Versioned System Description (Section 3) editor with subservice and bridge-letter tracking
04Continuous evidence connectors (AWS, Okta, CrowdStrike, GitHub and more)
05Auditor Review export — workflow history and outcome per control
06Three-role workflow with an HMAC-signed audit log
07Subservice organisation register with carve-out vs inclusive method tracking
08Cross-framework mapping to ISO 27001 and NIST CSF

SOC 2 — frequently asked questions

Does SentinelPanda support SOC 2 Type II?

Yes — the continuous evidence collection and append-only workflow history are built for demonstrating operating effectiveness over the observation period that Type II requires.

What is the difference between Type I and Type II here?

Type I assesses control design at a point in time. Type II assesses operating effectiveness over a 3 to 12 month window. The same control library and evidence support both, so you can start with Type I and progress to Type II without rebuilding.

Which Trust Services Criteria are covered?

The mandatory Security Common Criteria (CC1 through CC9) plus the four optional categories — Availability, Processing Integrity, Confidentiality, and Privacy — selected per workspace.

Does it generate the System Description (Section 3)?

Yes — the System Description editor produces Section 3 with company background, principal service commitments, system components, subservice organisations, complementary user-entity controls, and the control environment, exported in the format your CPA firm expects.

How does it handle subservice organisations and bridge letters?

Each subservice organisation is tracked with the controls you rely on, the SOC 2 you reviewed, and the bridge-letter status. You can also generate your own bridge letter for customers between reports.

Can our external auditor use it?

Yes — the Auditor Review export gives your CPA firm per-control status, evidence, and the full workflow history they need to test, without a separate handoff.

Will SOC 2 work overlap with ISO 27001 or NIST CSF?

Heavily — the cross-framework mapping means a control implemented for SOC 2 automatically credits its equivalents in ISO 27001 Annex A and NIST CSF, so you do not duplicate work when adding the next framework.

Start your SOC 2 program today.