Scrutineer.ai

Scrutineer · By framework

SOC 2 compliance for SaaS companies and SaaS startups

The security review is where enterprise deals stall. A procurement team asks for your SOC 2 Type 2 report, and without one the deal waits, or dies in a 300-question spreadsheet.

Scrutineer maps your controls to the Trust Services Criteria, collects evidence from your cloud and identity tools through the whole observation period, and tracks your subservice providers. Compliance software, not an audit.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with SOC 2 for SaaS

Your SOC 2 report covers your system, and AWS is usually carved out

Almost every SaaS company runs on AWS, Google Cloud or Azure, and almost every SaaS SOC 2 report treats that provider as a subservice organization under the carve-out method. That means your auditor does not test the data centers. Your system description names the provider, lists the complementary subservice organization controls you rely on it for, and your report covers everything above that line: your code, your access, your change management, your incident response. Two things follow that most first-time founders miss. First, the provider's own SOC 2 report does not make you compliant, it only covers the carved-out part. Second, the Common Criteria expect you to monitor that provider, which in practice means reading its current SOC 2 report every year and recording what you checked. The same applies to every other subservice organization in scope, from your identity provider to your payment processor.

Pick the Trust Services Criteria from your contracts, not from a template

Security, the Common Criteria, is in every SOC 2. The other four categories are optional, and adding one adds controls to build, evidence to collect and tests to pass for the whole observation period. The practical rule for a SaaS company is to read what your customer contracts and security questionnaires already promise. A published uptime SLA points to Availability. Holding customer source code, financials or other data under NDA points to Confidentiality. A product that calculates something customers rely on, such as billing, payroll or transactions, points to Processing Integrity. Privacy is rarely needed in a B2B product, because your customer usually controls the personal data. Adding a category nobody asked for will not win a deal, and leaving out one a customer relies on means the report does not answer their question.

What an enterprise buyer does with your SOC 2 report

A procurement or security team does not stop at the auditor's opinion. It reads the system description to confirm the product it is buying is in scope, scans the exceptions section for failed tests, checks the report period against today's date, and reads the complementary user entity controls to see what the report expects of the buyer. A report whose period ended eleven months ago gets a request for a bridge letter. A report with exceptions around access or change management gets follow-up questions. And a questionnaire often arrives anyway. Scrutineer keeps the controls, the evidence and your questionnaire answers on one library, so the report, the answers and the evidence tell the same story.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your controls to the 2017 Trust Services Criteria (with the revised 2022 points of focus), so a SaaS team sees exactly which criteria each control satisfies
  • Collects evidence continuously from your cloud, identity, code and ticketing tools through the whole Type 2 observation period, not in the two weeks before fieldwork
  • Flags a control that stopped producing evidence mid-period, while there is still time to fix it before the auditor samples that month
  • Keeps an inventory of subservice organizations and the complementary controls you rely on each for, ready for the system description
  • Records the annual review of each subservice provider's own SOC 2 report, which is the monitoring evidence auditors ask a carve-out company for
  • Tracks quarterly access reviews, change approvals, onboarding and offboarding, the controls where first SaaS audits most often find exceptions
  • Answers customer security questionnaires from the same mapped controls, so sales engineers stop rewriting answers for every deal
  • Adds ISO 27001, HIPAA, GDPR or PCI DSS on the same library when a new customer segment asks, with no second program
SOC 2 for SaaS readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Scoping a SaaS SOC 2

Which Trust Services Criteria a SaaS company should put in scope

Most SOC 2 for SaaS guides list the five categories and stop. The useful question is which ones your contracts already commit you to, because every category you add is tested for the whole observation period. Security is mandatory; the rest follow from what you sell.

Trust Services Criteria category Required in a SaaS SOC 2? Put it in scope when your SaaS What the auditor will test
Security (Common Criteria, CC1 to CC9) Yes, in every SOC 2 report Always, it is the baseline Access reviews, onboarding and offboarding, change management, vulnerability management, incident response, risk assessment and vendor monitoring
Availability (A1) Optional Publishes an uptime SLA, or customers run operations on your product Capacity monitoring, backups, restore tests and a tested recovery plan
Confidentiality (C1) Optional Holds customer data under NDA or contract, such as source code, financials or pricing How confidential data is identified, retained and disposed of when a contract ends
Processing Integrity (PI1) Optional Calculates or processes something customers rely on, such as billing, payroll or transactions Completeness and accuracy of inputs, processing and outputs, and error handling
Privacy (P1 to P8) Optional, and rare in B2B Collects personal information directly from consumers, rather than processing it for a business customer Notice, choice and consent, collection, use, access and disclosure of personal information
Subservice providers (AWS, Google Cloud, Azure) Handled in your system description Runs on a cloud provider you did not audit, which is almost every SaaS Carve-out: the complementary subservice organization controls you rely on, and evidence that you review the provider's own report

Good questions

Questions about SOC 2 for SaaS

No law requires it, but most US SaaS companies selling to mid-market and enterprise buyers need a SOC 2 report to get through security review. Procurement teams ask for it before signing, and without it you answer long security questionnaires deal by deal. For many B2B SaaS companies, SOC 2 Type 2 is the practical price of selling upmarket.
No. SOC 2 applies to any service organization whose controls affect its customers' data, including managed service providers, data centers, payment processors, payroll companies and outsourced support. SaaS companies are simply the largest group of SOC 2 buyers, because their customers' data lives on systems the customer does not control.
Security is required in every SOC 2 report. Add Availability if you publish an uptime SLA, Confidentiality if you hold customer data under NDA, and Processing Integrity if customers rely on your product's calculations. Privacy is rarely needed for B2B SaaS. Choose from what your contracts already promise, since each category adds controls tested for the whole period.
Sometimes, as a first step. A Type 1 shows your controls were designed properly on one date, and some buyers accept it to close a deal now. Most enterprise buyers expect a Type 2, which shows the controls operated over a period, usually three to twelve months. Many SaaS companies get a Type 1 and start the Type 2 period right away.
For a SaaS startup with controls mostly in place, readiness typically takes one to three months, a Type 1 can follow within weeks, and a first Type 2 covers an observation period of three to six months, followed by a few weeks of fieldwork and reporting. Plan six to nine months from start to a Type 2 report.
The audit fee alone usually runs $10,000 to $60,000 in the US, roughly $5,000 to $25,000 for a Type 1 and $15,000 to $70,000 for a Type 2 from a specialist CPA firm. With readiness work, tooling and a penetration test, most SaaS startups budget $25,000 to $80,000 in the first year.
No. The AWS SOC 2 report covers AWS's own controls over its infrastructure. Your SaaS report usually treats AWS as a carved-out subservice organization, and everything above that line is yours: access, code changes, configuration, logging, backups and incident response. You also need evidence that you review the AWS report each year.
No. SOC 2 is an attestation report issued by an independent CPA firm under AICPA standards, not a certification. There is no SOC 2 certificate or badge issued by a governing body. Buyers ask for the report itself, usually under NDA, and read the auditor's opinion, the system description and any exceptions.
No. Only a licensed CPA firm can issue a SOC 2 report. Scrutineer is compliance software: it maps your controls to the Trust Services Criteria, collects evidence through the observation period, tracks subservice providers and flags gaps before your auditor does. SOC 2 alone runs on the Essentials plan, and adding more frameworks on the same library is Growth.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification