SOC / Attestation

Available now

SOC 2 · 2017 TSC (rev. 2022)

SOC 2 is the attestation report North American buyers ask for most. It proves an independent auditor examined your controls against the Trust Services Criteria: Security, and optionally Availability, Confidentiality, Processing Integrity, and Privacy.

61

requirements tracked

Core plans

Access

Add-on from $39/mo

Scope

How much of the standard Keel models

Models its declared scope in full

Keel authors every leaf requirement in the scope declared below — all 61 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.

Authored in Keel
61 requirements
In Keel’s scored scope
61 leaf requirements

Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework

Who it is for

Who needs SOC 2?

  • SaaS and B2B companies whose deals stall on a security questionnaire
  • Startups asked for "your SOC 2" by a first enterprise customer
  • Teams choosing between a Type I (point-in-time) and Type II (over a period) report

What Keel does

How Keel helps with SOC 2

  • A curated control set mapped to the Trust Services Criteria, ready to tailor
  • Evidence collected once and reused across every other framework you add
  • A live readiness score so you always know how close you are to audit-ready

Collect once, comply everywhere

SOC 2 shares canonical controls with ISO/IEC 27001, NIST SP 800-53 and SOX (Sarbanes-Oxley) Section 404 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding SOC 2 rarely means starting from scratch.

Shares canonical controls with

  • ISO/IEC 27001
  • CIS Critical Security Controls
  • PCI DSS
  • SOX (Sarbanes-Oxley) Section 404
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • HIPAA
  • GDPR
  • COPPA
  • Google Play Families
  • Amazon Appstore Child-Directed Apps
  • Apple App Store Kids Category
  • ISO 9001
  • AI Governance Essentials
  • ISO/IEC 42001
  • NIST AI Risk Management Framework
  • EU AI Act
  • ESG Essentials
  • US Employment Law - Federal Baseline