SOC 2 (TSC 2017)
SOC 2, without starting from scratch
71 Trust Services Criteria across CC1–CC9, A1, C1 and PI1 (Privacy stubbed). Enable SOC 2 with a 71-entry cross-walk from your ISO 27001 controls, or a 40-control starter pack. Run Type I / Type II audit periods, draft the system description, and watch the readiness scorecard.
71
TSC criteria
71
cross-walk mappings
I & II
audit period types
- ISO 27001 → SOC 2 cross-walk
- 40-control starter pack
- Audit periods (Type I / II)
- System description + readiness
What’s in the module
71 criteria, two ways to start
71 Trust Services Criteria across CC1–CC9, A1, C1 and PI1 (Privacy stubbed). Enable from your ISO 27001 controls via the cross-walk, or stand alone with a 40-control starter pack.
- 01
ISO 27001 → SOC 2 cross-walk
Enable SOC 2 and 71 mappings carry your existing ISO 27001 control evidence straight onto the Trust Services Criteria. No starting from zero.
- 02
40-control starter pack
Not on ISO 27001 yet? Start SOC 2 standalone with a 40-control starter pack and build from there.
- 03
Audit periods (Type I / II)
Create and manage Type I and Type II periods with their lifecycle, so the evidence window is explicit and tracked.
- 04
System description + readiness
A Section II system-description editor and a readiness scorecard that shows, criterion by criterion, where you stand before the auditor arrives.
The wedge
The ISO 27001 → SOC 2 cross-walk, in about 60 seconds
Enable SOC 2 on a workspace that already has ISO 27001 and 71 mappings carry your control evidence straight onto the Trust Services Criteria. Watch one control light up the criteria it satisfies.
- 71
- mappings
- ~3 wks
- work removed
- 1
- evidence set
ISO 27001
SOC 2 — TSC
Access control policy · joiner/leaver records · quarterly access reviews
Readiness scorecard
See where you stand criterion by criterion before the auditor arrives. The AI readiness analyser writes a narrative verdict for each criterion and persists snapshots, so you can watch readiness move as you close gaps.
System description, drafted
The Section II system-description editor gives you a structured place to write it — and the AI drafter proposes a first version from your asset register and controls, for you to edit and own.
Type I and Type II periods
Create and manage audit periods with their lifecycle, so the observation window is explicit and the evidence that belongs to it is tracked against it.
~77-question audit bank
Run internal walkthroughs against a SOC 2 question bank, with per-question AI suggestions drawn from the linked controls and recent activity.
When a pure SOC 2 tool is the better fit
We’ll be straight with you: if your only goal is the fastest possible first SOC 2 report, with deep automated evidence collection and warm auditor introductions, tools like Vanta and Drata are purpose-built for exactly that and have the brand and auditor relationships to match.
Obligara wins when SOC 2 isn’t the whole story — when you want it to sit on a richer QMS and ISMS you’ll keep using, with one cross-walk doing the work across frameworks, at a sensible UK price.
See the honest comparison vs VantaSee SOC 2 readiness on your evidence
Bring your ISO 27001 controls (or none at all) and we’ll show you the cross-walk and readiness scorecard live.