SOC / Attestation
Available nowSOC 2 · 2017 TSC (rev. 2022)
SOC 2 is the attestation report North American buyers ask for most. It proves an independent auditor examined your controls against the Trust Services Criteria: Security, and optionally Availability, Confidentiality, Processing Integrity, and Privacy.
61
requirements tracked
Core plans
Access
Add-on from $39/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below — all 61 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 61 requirements
- In Keel’s scored scope
- 61 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs SOC 2?
- SaaS and B2B companies whose deals stall on a security questionnaire
- Startups asked for "your SOC 2" by a first enterprise customer
- Teams choosing between a Type I (point-in-time) and Type II (over a period) report
What Keel does
How Keel helps with SOC 2
- A curated control set mapped to the Trust Services Criteria, ready to tailor
- Evidence collected once and reused across every other framework you add
- A live readiness score so you always know how close you are to audit-ready
Collect once, comply everywhere
SOC 2 shares canonical controls with ISO/IEC 27001, NIST SP 800-53 and SOX (Sarbanes-Oxley) Section 404 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding SOC 2 rarely means starting from scratch.
Shares canonical controls with
- ISO/IEC 27001
- CIS Critical Security Controls
- PCI DSS
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- HIPAA
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
Features that help with SOC 2: Risk register · Policy management · Vendor risk management · Controls & crosswalk · Evidence management
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · NIST SP 800-53 · All frameworks