Scrutineer · By framework
SOC 2 compliance that gets you audit-ready, with evidence
SOC 2 compliance is mostly a paperwork problem disguised as a security problem: you already run access reviews, change management and monitoring, but proving it to an auditor means chasing screenshots, tickets and logs for weeks. Scrutineer maps your existing controls to the five Trust Services Criteria, then collects the evidence behind each one automatically.
As systems change, Scrutineer keeps the mapping current and flags gaps the moment a control drifts, so nothing surprises you in the audit. You see a live readiness view per criterion, the exact evidence attached to each control, and a prioritized list of what to fix first. Scrutineer gets you ready, and your accredited auditor issues the attestation.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with SOC 2 compliance
You choose the scope, and the scope decides most of the work
The single largest driver of SOC 2 effort is a decision made before any control is tested. Security, the common criteria, is in every SOC 2. Availability, confidentiality, processing integrity and privacy are optional categories that management selects, and each one you add brings its own criteria, its own evidence and its own testing. Management also writes the system description that defines which products, environments, locations and people are inside the boundary. Auditors test against what you asserted, not against everything you own. Teams that scope late usually scope wide, because nobody wants to argue about a boundary once the audit has started, and then they spend the year collecting evidence for criteria no customer ever asked about. Scope deliberately, write the boundary down, and make the sales team confirm which categories customers are actually requesting before you commit to them.
Evidence has a date, and the date is what fails
Most control failures in a Type 2 are not design failures. The control existed and the team ran it, but the artifact proving one instance was never captured, or was captured for a different quarter. A Type 2 opinion covers a period, so the auditor samples across it and a missing month is a missing month. This is why evidence collection has to be continuous rather than a project. Access reviews, change approvals, vulnerability remediation, backup restoration tests, vendor reviews and security training all have to leave a dated artifact each time they happen, attached to the control they prove. Scrutineer pulls that evidence from the systems where the work actually happens and timestamps it against the control, so the population you hand the auditor matches the period under review rather than the week you started collecting.
Readiness is our job. The opinion is a licensed CPA firm decision
Only a licensed CPA firm can perform a SOC 2 examination and issue the report, and the opinion in that report is theirs alone. No platform, ours included, can shorten that or influence it. What tooling legitimately changes is everything on your side of the line: whether the control set maps cleanly to the criteria you selected, whether evidence exists for every period sampled, whether gaps were found in month two rather than in fieldwork, and whether the auditor spends their hours testing rather than chasing files. That is also why you should be suspicious of any vendor language implying certification. SOC 2 is an attestation engagement and produces a report with an opinion, not a certificate, and there is no body that certifies anyone against it.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your existing controls to the Trust Services Criteria you actually selected, so you stop collecting evidence for categories nobody asked for
- Collects evidence from cloud, identity, ticketing and HR systems and timestamps each artifact against the control it proves
- Shows live readiness per criterion, with the specific evidence behind every green state rather than a percentage
- Flags drifted controls and stale evidence during the period, when a gap is still fixable, instead of in fieldwork
- Keeps the system description boundary explicit, because scope is the decision that drives most of the cost
- Prioritizes gaps by how likely they are to become an exception in the report, not by how easy they are to close
- Hands the auditor an organized, dated population per control, which is the part that shortens fieldwork
- Reuses the same control library for ISO 27001, HIPAA, PCI DSS and vendor risk, so the second framework costs a fraction of the first
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
SOC 2 report reference
What a SOC 2 report actually asserts, line by line, against what people assume
Nearly every published SOC 2 table compares Type 1 with Type 2, or lists the five Trust Services Categories. Both are true and neither helps when a report is on your desk. The useful axis is the gap between what a reader assumes the report proves and what it says, because that gap is where vendor reviews and sales cycles go wrong in both directions.
| What a SOC 2 report is assumed to prove | What it actually asserts | Who decided that | Where to look in the report |
|---|---|---|---|
| The vendor is secure | That controls the vendor itself selected were suitably designed, and for a Type 2 operated effectively over a stated period, against the criteria in scope | The vendor selected the criteria and wrote the control set. The CPA firm opined on that set | The opinion paragraph, then management assertion, then the control listing in section 4 |
| The scope covers the product I use | Only if the system description names it. Anything outside the described boundary was never in the engagement | Management wrote the system description and the boundary | Section 3, the description of the system: products, environments, locations and in-scope infrastructure |
| All five Trust Services Categories were examined | Security, the common criteria, is always included. Availability, confidentiality, processing integrity and privacy appear only if management selected them | Management, at scoping time, usually months before you saw the report | The opinion paragraph, which names the categories in scope, and the criteria headings in section 4 |
| There were no problems | An unqualified opinion and a clean testing section are different things. Exceptions can be listed in the test results under an unqualified opinion | The CPA firm judged severity. You judge whether it matters to you | Every row of section 4 that says exceptions noted, plus management response |
| It reflects the vendor today | It reflects a period that already ended. The gap between period end and today is covered by nothing | Nobody. A bridge letter covering the gap is a management representation, not audit work | The period covered on the cover page, then the date of any bridge letter and who signed it |
| The vendor subservice providers were tested too | Under the carve-out method they were not. The report names them and lists the controls assumed of them, and the auditor tested none of those | Management chose carve-out or inclusive. Carve-out is far more common | The subservice organization section and the complementary subservice organization controls |
| The vendor is SOC 2 certified | Nobody is. SOC 2 is an attestation engagement that produces a report and an opinion. There is no certificate and no certifying body | The AICPA attestation standards the engagement is performed under | The report itself. If a vendor sends you a certificate instead of a report, ask for the report |
This table describes the standard structure of a SOC 2 report under the AICPA attestation standards and the 2017 Trust Services Criteria. Individual reports vary, and only the report in front of you governs what it says, so read the opinion, the system description and the test results rather than a summary of them. Scrutineer prepares readiness evidence; a licensed, independent CPA firm performs the examination and issues the opinion.
Good questions
Questions about SOC 2 compliance
Keep reading
Guides that go deeper on SOC 2 compliance
SOC 2 audit checklist
The controls and evidence an auditor works through, in the order they ask for them.
Read the guideSOC 2 Type 1 vs Type 2
Which report your customers actually want, and what each one costs you in time.
Read the guideHow much a SOC 2 audit costs
Reported figures for the examination and the readiness work, and the variables that move the number.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreHIPAA compliance software
Map the HIPAA Security Rule safeguards, automate evidence, and track BAAs.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification