Compliance Framework

SOC 2 (System and Organization Controls)

The trust standard Software as a Service (SaaS) and cloud vendors are asked to prove, and logical access control is one of its most tested areas.

What is SOC 2?

SOC 2 (System and Organization Controls) is an AICPA auditing standard built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. A SOC 2 Type II report demonstrates that your controls didn't just exist on paper: they operated effectively over a period of months.

Logical access control sits at the heart of the Security criterion: who can access what, how access is granted and revoked, and how privileged access is monitored are among the most commonly requested evidence sets in any SOC 2 audit.

A Type II report tests operating effectiveness over a period (typically 6-12 months) so access control evidence has to be produced consistently across that whole window, not assembled retroactively before the audit starts. The most common finding we see isn't a missing control, it's one that existed but wasn't followed consistently: a leaver whose access was revoked days late, or a privileged account created outside the normal request workflow during an incident and never reconciled afterward. Auditors sample; a handful of exceptions like these across a 12-month window is enough to qualify an otherwise-clean report.

How IAM Tech helps

We build the access governance and privileged access processes that generate SOC 2 evidence continuously, so the audit period isn't a scramble to retrofit documentation.

  • Access provisioning and de-provisioning processes with an audit trail
  • Privileged access vaulting, rotation, and session monitoring
  • Scheduled access certification campaigns auditors can sample directly
  • Evidence packs mapped to Trust Services Criteria
See Compliance & Audit Readiness →

Common questions

What's the difference between SOC 2 Type I and Type II?

Type I tests whether controls are suitably designed at a single point in time. Type II tests whether they actually operated effectively over a period, usually 6-12 months. Type II is the one most enterprise customers and due-diligence teams actually require, because it tests consistency, not just design.

Does SOC 2 require multi-factor authentication?

Not explicitly by name, but the Security criterion's common criteria require logical access controls appropriate to the risk, and in practice auditors treat MFA (especially for privileged and remote access) as close to a baseline expectation for a clean report.

How far in advance should access control processes be in place before a SOC 2 audit?

For a Type II report, at least as long as the observation period itself: if the audit covers a 6-month window, the access review, provisioning, and deprovisioning processes need to have been running consistently for that full 6 months before the audit can test them.

Want to know where you stand?

Take the free 2-minute IAM Health Check, or talk to us directly about your SOC 2 requirements.

Talk to us
Talk to us