Skip to content

SOC 2 Security Library

Manage SOC 2 Security Common Criteria gaps, evidence, control ownership, remediation, testing, and readiness decisions.

The SOC 2 Security library represents the Common Criteria that form the foundation of a SOC 2 engagement. These criteria examine whether controls provide reasonable assurance that systems and information are protected against unauthorized access, use, disclosure, disruption, modification, or destruction.

Standards and scope

The configured library follows the AICPA Trust Services Criteria structure and organizes work across CC1 through CC9. Other categories extend this foundation but do not replace it.

  • CC1 and CC2 cover the control environment and information and communication.
  • CC3 and CC4 cover risk assessment and monitoring activities.
  • CC5 addresses the selection and development of control activities.
  • CC6 addresses logical and physical access controls.
  • CC7, CC8, and CC9 address system operations, change management, and risk mitigation.

Who this is for

  • GRC students and teams learning how criteria connect to controls, evidence, tests, and exceptions.
  • Security and compliance leaders preparing a service organization for SOC 2.
  • Control owners responsible for access, operations, changes, monitoring, and risk treatment.
  • Consultants and internal reviewers coordinating readiness across several departments.

What voiqq provides

  • Canonical Common Criteria references and consistent finding fields.
  • Evidence-request, population, sample, test, exception, and remediation records in one workspace.
  • Control-owner assignment, due dates, comments, attachments, status, and validation.
  • Spreadsheet normalization for existing gap trackers without losing the original source grid.
  • Readiness report snapshots that preserve the reviewed state at generation time.

A practical workflow

  1. Confirm the service, system boundaries, subservice organizations, and Security scope.
  2. Connect existing controls and evidence to the relevant Common Criteria.
  3. Document missing, incomplete, or ineffective controls as findings or evidence gaps.
  4. Track remediation and obtain updated evidence from the accountable owner.
  5. Validate closure and review remaining exceptions with the engagement team.

Put the framework into practice

A structured Security project makes it easier to see which criteria are supported, which evidence remains outstanding, and where an unresolved control gap could affect readiness.

Start free

Review the AICPA criteria resource