SOC 2 controls tracker
Work through the AICPA Trust Services Criteria — the Common Criteria (CC1–CC9, Security) plus Availability, Confidentiality, Processing Integrity, and Privacy — set a status and capture your evidence against each. Your progress is saved in this browser. Use it to build your controls matrix and evidence trail.
0%
conformance
Getting started
Set a status on each item below. Conformant counts fully, partial counts half, and “N/A” items are excluded from the score.
Scope & accuracy. This tracker paraphrases the AICPA Trust Services Criteria in plain language for working purposes; it does not reproduce the criteria. Identifiers are for orientation and should be validated against the official AICPA criteria and your auditor. Status here is a self-assessment and is not a SOC 2 examination or report.