Security Questionnaire Mapper
Framework

SOC 2 (Trust Services Criteria): what it anchors in a questionnaire

The attestation US customers ask for by name. A question that names SOC 2 reaches past an ISO 27001 certificate even where the topic is the same.

The criteria text is not held in full here, so it is not quoted: each criterion is named by its code and title, with the evidence an assessor usually asks for. Ticked by default for bank, hospital or health plan, card merchant or payment processor, software company and other customer customers.

Families anchored here

16 families, 12 clauses cited
FamilyClause
Information security policyCC5.3
Risk assessmentCC3.2
Independent audit and certificationCC4.1
Multi-factor authenticationCC6.1
Password policyCC6.1
Access provisioning and reviewCC6.2
Encryption at restCC6.1
Logging and monitoringCC7.2
Vulnerability and patch managementCC7.1
Secure development and changeCC8.1
Incident response planCC7.4
Notifying the customer of an incidentCC7.4
Business continuity planA1.3
Backup and disaster recoveryA1.2
Subcontractors and subprocessorsCC9.2
Assessing your own suppliersCC9.2

Every SOC 2 clause the register cites, with its text and evidence