Scrutineer · By framework
SOC 2 compliance for SaaS companies and SaaS startups
The security review is where enterprise deals stall. A procurement team asks for your SOC 2 Type 2 report, and without one the deal waits, or dies in a 300-question spreadsheet.
Scrutineer maps your controls to the Trust Services Criteria, collects evidence from your cloud and identity tools through the whole observation period, and tracks your subservice providers. Compliance software, not an audit.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with SOC 2 for SaaS
Your SOC 2 report covers your system, and AWS is usually carved out
Almost every SaaS company runs on AWS, Google Cloud or Azure, and almost every SaaS SOC 2 report treats that provider as a subservice organization under the carve-out method. That means your auditor does not test the data centers. Your system description names the provider, lists the complementary subservice organization controls you rely on it for, and your report covers everything above that line: your code, your access, your change management, your incident response. Two things follow that most first-time founders miss. First, the provider's own SOC 2 report does not make you compliant, it only covers the carved-out part. Second, the Common Criteria expect you to monitor that provider, which in practice means reading its current SOC 2 report every year and recording what you checked. The same applies to every other subservice organization in scope, from your identity provider to your payment processor.
Pick the Trust Services Criteria from your contracts, not from a template
Security, the Common Criteria, is in every SOC 2. The other four categories are optional, and adding one adds controls to build, evidence to collect and tests to pass for the whole observation period. The practical rule for a SaaS company is to read what your customer contracts and security questionnaires already promise. A published uptime SLA points to Availability. Holding customer source code, financials or other data under NDA points to Confidentiality. A product that calculates something customers rely on, such as billing, payroll or transactions, points to Processing Integrity. Privacy is rarely needed in a B2B product, because your customer usually controls the personal data. Adding a category nobody asked for will not win a deal, and leaving out one a customer relies on means the report does not answer their question.
What an enterprise buyer does with your SOC 2 report
A procurement or security team does not stop at the auditor's opinion. It reads the system description to confirm the product it is buying is in scope, scans the exceptions section for failed tests, checks the report period against today's date, and reads the complementary user entity controls to see what the report expects of the buyer. A report whose period ended eleven months ago gets a request for a bridge letter. A report with exceptions around access or change management gets follow-up questions. And a questionnaire often arrives anyway. Scrutineer keeps the controls, the evidence and your questionnaire answers on one library, so the report, the answers and the evidence tell the same story.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your controls to the 2017 Trust Services Criteria (with the revised 2022 points of focus), so a SaaS team sees exactly which criteria each control satisfies
- Collects evidence continuously from your cloud, identity, code and ticketing tools through the whole Type 2 observation period, not in the two weeks before fieldwork
- Flags a control that stopped producing evidence mid-period, while there is still time to fix it before the auditor samples that month
- Keeps an inventory of subservice organizations and the complementary controls you rely on each for, ready for the system description
- Records the annual review of each subservice provider's own SOC 2 report, which is the monitoring evidence auditors ask a carve-out company for
- Tracks quarterly access reviews, change approvals, onboarding and offboarding, the controls where first SaaS audits most often find exceptions
- Answers customer security questionnaires from the same mapped controls, so sales engineers stop rewriting answers for every deal
- Adds ISO 27001, HIPAA, GDPR or PCI DSS on the same library when a new customer segment asks, with no second program
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Scoping a SaaS SOC 2
Which Trust Services Criteria a SaaS company should put in scope
Most SOC 2 for SaaS guides list the five categories and stop. The useful question is which ones your contracts already commit you to, because every category you add is tested for the whole observation period. Security is mandatory; the rest follow from what you sell.
| Trust Services Criteria category | Required in a SaaS SOC 2? | Put it in scope when your SaaS | What the auditor will test |
|---|---|---|---|
| Security (Common Criteria, CC1 to CC9) | Yes, in every SOC 2 report | Always, it is the baseline | Access reviews, onboarding and offboarding, change management, vulnerability management, incident response, risk assessment and vendor monitoring |
| Availability (A1) | Optional | Publishes an uptime SLA, or customers run operations on your product | Capacity monitoring, backups, restore tests and a tested recovery plan |
| Confidentiality (C1) | Optional | Holds customer data under NDA or contract, such as source code, financials or pricing | How confidential data is identified, retained and disposed of when a contract ends |
| Processing Integrity (PI1) | Optional | Calculates or processes something customers rely on, such as billing, payroll or transactions | Completeness and accuracy of inputs, processing and outputs, and error handling |
| Privacy (P1 to P8) | Optional, and rare in B2B | Collects personal information directly from consumers, rather than processing it for a business customer | Notice, choice and consent, collection, use, access and disclosure of personal information |
| Subservice providers (AWS, Google Cloud, Azure) | Handled in your system description | Runs on a cloud provider you did not audit, which is almost every SaaS | Carve-out: the complementary subservice organization controls you rely on, and evidence that you review the provider's own report |
Good questions
Questions about SOC 2 for SaaS
Keep reading
Guides that go deeper on this framework
SOC 2 audit cost
What SaaS companies actually pay for the audit, readiness and tooling in year one.
Read the guideSOC 2 Type 1 vs Type 2
Which report your buyers expect, and how the observation period sets your timeline.
Read the guideBest SOC 2 compliance software
Six platforms compared for SaaS teams preparing their first audit.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification