SOC 2, without the $30k platform.

All 358 Trust Services Criteria, evidence tied to controls, and a portal your auditor can actually use.

Why SOC 2 goes wrong

SOC 2 is not hard to understand. It is hard to sustain. You pass a Type I, everyone relaxes, and twelve months later the Type II observation window has been running the whole time on evidence nobody collected.

The Trust Services Criteria are also broader than most first-timers expect. The Common Criteria alone run to nine control families covering governance, risk assessment, monitoring, access, operations and change management — before you add Availability, Confidentiality or Privacy.

OpenGRC includes the full SOC 2 (TSC 2017, with the 2022 revision) bundle — 358 criteria — on every plan, alongside 172 other frameworks at no extra cost.

Built for Type II

Survive the observation window.

Evidence that accumulates

Evidence that accumulates

A Type II is judged on twelve months of operation, not a snapshot. Set an assessment cadence per control, automate the recurring reviews, and let workflow rules chase what is overdue so the evidence exists when the auditor asks.

One control, many frameworks

One control, many frameworks

Most SOC 2 criteria overlap with ISO 27001 and others you may already carry. OpenGRC aggregates coverage across every framework you import, so you satisfy a control once rather than once per report.

A portal for your auditor

A portal for your auditor

Give your audit firm their own MFA-protected panel with time-bounded, revocable access, IP allow-listing and immutable versioned submissions, instead of a shared drive and a spreadsheet of requests.

The Trust Services Criteria, and where they live

CriteriaControls in the bundle
CC1 Control environment31
CC2 Communication and information29
CC3 Risk assessment38
CC4 Monitoring activities13
CC5 Control activities19
CC6 Logical and physical access42
CC7 System operations38
CC8 Change management16
CC9 Risk mitigation16
A1 Availability18
C1 Confidentiality6
P1–P8 Privacy69

Import the Common Criteria alone, or add Availability, Confidentiality and Privacy depending on the scope you have committed to. Each criterion connects to your implementations, evidence and risks.

SOC 2 questions

Does OpenGRC issue a SOC 2 report?

No — only a licensed CPA firm can do that. OpenGRC is where you run the program that gets you through the audit: the criteria, your control implementations, the evidence, the gaps and the auditor's access.

Type I or Type II?

Is SOC 2 an add-on?

We also need ISO 27001. Do we do the work twice?