> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SOC 2

> Achieve SOC 2 compliance with automated controls, evidence collection, and audit preparation.

SOC 2 (System and Organization Controls 2) is a security framework developed by the American Institute of CPAs (AICPA). It defines criteria for managing customer data based on five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

<Note>
  SOC 2 is the most widely requested compliance framework for SaaS companies and technology service providers selling to mid-market and enterprise customers.
</Note>

## Who needs SOC 2?

<CardGroup cols={2}>
  <Card title="SaaS companies" icon="cloud">
    Any software company that stores, processes, or transmits customer data. Enterprise buyers increasingly require SOC 2 reports before signing contracts.
  </Card>

  <Card title="Service providers" icon="server">
    Cloud hosting providers, managed service providers, data centers, and organizations handling sensitive client data.
  </Card>
</CardGroup>

## The 5 Trust Service Criteria

<CardGroup cols={3}>
  <Card title="Security" icon="shield">
    **Required for all SOC 2 audits.** Protection of systems and data against unauthorized access — firewalls, intrusion detection, MFA, and access controls.
  </Card>

  <Card title="Availability" icon="signal">
    Systems are operational and accessible as agreed. Covers uptime monitoring, disaster recovery, and business continuity.
  </Card>

  <Card title="Processing Integrity" icon="check-double">
    System processing is complete, accurate, timely, and authorized. Covers quality assurance and error monitoring.
  </Card>

  <Card title="Confidentiality" icon="eye-slash">
    Information designated as confidential is protected through encryption, access restrictions, and data classification.
  </Card>

  <Card title="Privacy" icon="user-shield">
    Personal information is collected, used, retained, and disclosed in conformity with commitments and privacy policies.
  </Card>
</CardGroup>

## SOC 2 Type I vs Type II

|                    | Type I                            | Type II                                                  |
| ------------------ | --------------------------------- | -------------------------------------------------------- |
| **What it covers** | Control design at a point in time | Control design AND operating effectiveness over a period |
| **Audit period**   | Single date                       | Typically 3–12 months                                    |
| **Strength**       | Faster to achieve                 | Stronger assurance for customers                         |
| **Best for**       | First-time SOC 2                  | Ongoing compliance proof                                 |

<Tip>
  Most enterprise customers require a **Type II** report. Start with Type I if you need something fast, then transition to Type II for ongoing assurance.
</Tip>

## How DSALTA helps with SOC 2

<Steps>
  <Step title="Activate SOC 2">
    Select SOC 2 from the Frameworks page. DSALTA maps all 9 areas and 33 criteria to pre-built controls automatically.
  </Step>

  <Step title="Review mapped controls">
    DSALTA maps 80+ controls to SOC 2 criteria. Review each control, mark non-applicable ones, and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect your integrations (AWS, GCP, GitHub, Google Workspace). DSALTA runs automated tests and collects evidence continuously.
  </Step>

  <Step title="Approve policies">
    AI-generated policies are pre-mapped to SOC 2 requirements. Review, customize, and approve each one.
  </Step>

  <Step title="Prepare for audit">
    Create an audit, invite your auditor, and share evidence directly through the platform. Track auditor feedback in real time.
  </Step>
</Steps>

## Key SOC 2 areas in DSALTA

| Area                                 | Example Controls                                           |
| ------------------------------------ | ---------------------------------------------------------- |
| **CC 1.0 Control Environment**       | Board oversight, organizational structure, code of conduct |
| **CC 2.0 Communication**             | Internal/external communication of security policies       |
| **CC 3.0 Risk Assessment**           | Risk identification, fraud risk evaluation                 |
| **CC 4.0 Monitoring**                | Continuous monitoring, internal audits                     |
| **CC 5.0 Control Activities**        | Access controls, change management, segregation of duties  |
| **CC 6.0 Logical & Physical Access** | Authentication, MFA, physical security                     |
| **CC 7.0 System Operations**         | Incident management, vulnerability scanning                |
| **CC 8.0 Change Management**         | Change approval, testing, deployment controls              |
| **CC 9.0 Risk Mitigation**           | Vendor management, business continuity                     |

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How long does it take to get SOC 2 compliant?" icon="clock">
    With DSALTA, most organizations achieve Type I readiness in 4–8 weeks. Type II requires a monitoring period of 3–12 months after controls are in place.
  </Accordion>

  <Accordion title="Do I need SOC 2 Type I first?" icon="circle-question">
    Not necessarily. Some organizations go directly to Type II if they have mature security practices. However, Type I is faster for initial compliance proof.
  </Accordion>

  <Accordion title="How much does a SOC 2 audit cost?" icon="dollar-sign">
    External audits typically cost $15,000–$50,000 depending on your organization's size and complexity. DSALTA reduces audit prep time significantly, saving on consulting costs.
  </Accordion>

  <Accordion title="Which Trust Service Criteria should I include?" icon="list-check">
    Security is mandatory. Add Availability if you have uptime SLAs, Confidentiality if you handle sensitive data, and Privacy if you process personal information.
  </Accordion>

  <Accordion title="Can DSALTA help me find an auditor?" icon="user-tie">
    DSALTA integrates with auditor workflows. Invite any CPA firm as your auditor and they receive a dedicated view of your evidence and controls.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**368** of DSALTA's automated checks contribute evidence to this framework, drawn from **73** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
