Compliance · cross-mapped
Control Library
47 controls in scope for SOC 2 Type II — every control owned, tested continuously, evidenced automatically and cross-mapped to ISO 27001, NIST CSF and CIS v8.
18 controls shown · 8 families
Catalog
| ID | Family | Control | Test | Mapped to |
|---|---|---|---|---|
| AC-01 | Access | Role-based access with quarterly recertification | continuous | SOC2 CC6.1ISO A.9.2NIST PR.AC-1 |
| AC-02 | Access | MFA enforced on all production and SaaS surfaces | continuous | SOC2 CC6.6ISO A.9.4CIS 6.5 |
| AC-03 | Access | Privileged access ephemeral · max 60 min | continuous | SOC2 CC6.3NIST PR.AC-4 |
| AC-04 | Access | Segregation of duties enforced in product | continuous | SOC2 CC6.1ISO A.6.1.2 |
| CH-01 | Change | All production changes peer-reviewed and CI-gated | continuous | SOC2 CC8.1ISO A.12.1.2 |
| CH-02 | Change | Infrastructure-as-code with drift detection | continuous | SOC2 CC8.1NIST PR.IP-1 |
| OP-01 | Operations | 24/7 on-call · MTTA under 5 min for SEV-1 | monthly | SOC2 A1.2ISO A.16.1 |
| OP-02 | Operations | Audit log immutable, 7-year retention | continuous | SOC2 CC7.2ISO A.12.4 |
| OP-03 | Operations | Anomaly detection on production money movement | continuous | SOC2 CC7.3 |
| RM-01 | Risk | Quarterly enterprise risk review | quarterly | SOC2 CC3.1ISO Clause 6 |
| RM-02 | Risk | Threat model refreshed per major release | quarterly | SOC2 CC3.2NIST ID.RA |
| DT-01 | Data | Encryption at rest (AES-256) and in transit (TLS 1.3) | continuous | SOC2 CC6.7ISO A.10 |
| DT-02 | Data | Data classification and DLP on sensitive egress | continuous | SOC2 CC6.7ISO A.8.2 |
| DT-03 | Data | Tenant isolation tested per release | continuous | SOC2 CC6.1 |
| VN-01 | Vendor | Subprocessor due diligence + 30-day notification | quarterly | SOC2 CC9.2ISO A.15 |
| BC-01 | BC/DR | Quarterly DR exercise · RTO 4h / RPO 15min | quarterly | SOC2 A1.2ISO A.17 |
| BC-02 | BC/DR | Multi-region active-active for money-moving APIs | continuous | SOC2 A1.2 |
| PR-01 | Privacy | Data subject rights fulfilled within 5 business days | monthly | GDPR Art.12ISO A.18.1.4 |
Continuous, not annual
Evidence is collected automatically — not assembled the week before audit.
Each control has a named owner, a runbook, and an automated test that produces evidence into our SOC 2 evidence pipeline. Our auditors see the same dashboard we do.