SOC 2 Preparation
Status: DRAFT Owner: Engineering Last Review: 2026-05-03 Applicable Standards: SOC 2 Type II (AICPA Trust Service Criteria 2017)
1. Purpose
SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA that evaluates an organization’s controls relevant to security, availability, processing integrity, confidentiality, and privacy. This document maps Equa’s current controls to the SOC 2 Trust Service Criteria, identifies gaps, and provides a remediation roadmap toward Type II readiness.2. Scope
3. Common Criteria Control Summary
The following table maps SOC 2 Common Criteria (CC) control IDs to their current implementation status. Detailed coverage is provided in the sections below and in the referenced compliance documents.Additional Criteria
4. Trust Service Criteria Detail
4.1 Security (CC6)
Security controls protect the system against unauthorized access. Current Controls:
Gaps:
4.2 Availability (A1)
Availability controls ensure the system is operational and accessible as committed. Current Controls:
Gaps:
4.3 Confidentiality (C1)
Confidentiality controls protect information designated as confidential. Current Controls:
Gaps:
4.4 Processing Integrity (PI1)
Processing integrity controls ensure that system processing is complete, valid, accurate, and timely. Current Controls:
Gaps:
4.5 Privacy (P1)
Privacy controls address the collection, use, retention, disclosure, and disposal of personal information. Current Controls:
Gaps: