SOC 2, without the $30k platform.
All 358 Trust Services Criteria, evidence tied to controls, and a portal your auditor can actually use.
Why SOC 2 goes wrong
SOC 2 is not hard to understand. It is hard to sustain. You pass a Type I, everyone relaxes, and twelve months later the Type II observation window has been running the whole time on evidence nobody collected.
The Trust Services Criteria are also broader than most first-timers expect. The Common Criteria alone run to nine control families covering governance, risk assessment, monitoring, access, operations and change management — before you add Availability, Confidentiality or Privacy.
OpenGRC includes the full SOC 2 (TSC 2017, with the 2022 revision) bundle — 358 criteria — on every plan, alongside 172 other frameworks at no extra cost.
Survive the observation window.
Evidence that accumulates
A Type II is judged on twelve months of operation, not a snapshot. Set an assessment cadence per control, automate the recurring reviews, and let workflow rules chase what is overdue so the evidence exists when the auditor asks.
One control, many frameworks
Most SOC 2 criteria overlap with ISO 27001 and others you may already carry. OpenGRC aggregates coverage across every framework you import, so you satisfy a control once rather than once per report.
A portal for your auditor
Give your audit firm their own MFA-protected panel with time-bounded, revocable access, IP allow-listing and immutable versioned submissions, instead of a shared drive and a spreadsheet of requests.
The Trust Services Criteria, and where they live
| Criteria | Controls in the bundle |
|---|---|
| CC1 Control environment | 31 |
| CC2 Communication and information | 29 |
| CC3 Risk assessment | 38 |
| CC4 Monitoring activities | 13 |
| CC5 Control activities | 19 |
| CC6 Logical and physical access | 42 |
| CC7 System operations | 38 |
| CC8 Change management | 16 |
| CC9 Risk mitigation | 16 |
| A1 Availability | 18 |
| C1 Confidentiality | 6 |
| P1–P8 Privacy | 69 |
Import the Common Criteria alone, or add Availability, Confidentiality and Privacy depending on the scope you have committed to. Each criterion connects to your implementations, evidence and risks.
SOC 2 questions
Does OpenGRC issue a SOC 2 report?
No — only a licensed CPA firm can do that. OpenGRC is where you run the program that gets you through the audit: the criteria, your control implementations, the evidence, the gaps and the auditor's access.
™