Company Profile
This information appears in the Executive Summary of the generated report.
Both levels assess all 61 criteria of the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022): the Security Common Criteria plus Availability, Processing Integrity, Confidentiality and Privacy. SOC 2 Type II adds an Evidence (12 Months) field to every criterion so you can type or insert links to evidence artifacts covering the last 12 months.
Include: what the company does, technology stack used, and products and services offered.
For each Trust Services Criterion select a status. For Partially Compliant or Non-Compliant items, rate the Likelihood and Impact of the risk the gap exposes (1 = lowest, 5 = highest). Risk Score = Likelihood × Impact. For SOC 2 Type II, use the Evidence (12 Months) field on each criterion to type or insert links to evidence artifacts covering the last 12 months.
Risk-Ranked Gaps
Generate Report
The report includes a cover page with the company logo, an Executive Summary, a Detailed Findings section covering every assessed Trust Services Criterion, and a Remediation Roadmap. SOC 2 Type II assessments include your Evidence (12 Months) links in the Detailed Findings.