Skip to content

Compliance matrix

SOC 2 (AICPA Trust Services Criteria)

United States (globally recognized) · Updated 2026-07-19

Applies to: SaaS and cloud vendors that need to prove security controls to enterprise customers.

Vendor certification snapshot

SOC 2 Type II status across the 48 vendors we track, read live from each profile.

40

Certified

3

Partial

5

Not stated

Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.

Requirements mapped to CIAM

Logical access controls (CC6.1)

Access to systems and customer data must be restricted to authorized users and enforced by identity controls.

CIAM controls

  • Role-based access with least privilege
  • Unique user identities, no shared accounts
  • Provisioning and deprovisioning tied to joiner/mover/leaver events

Evidence

  • Access review records
  • Role-to-permission mappings
  • Deprovisioning logs on offboarding

Ask the vendor

  • Do you support RBAC and least-privilege roles for administrators?
  • Can access be provisioned and revoked via SCIM?

Authentication strength (CC6.1)

Users and administrators must authenticate with controls proportional to risk.

CIAM controls

  • MFA for administrative and privileged access
  • Phishing-resistant options (passkeys / WebAuthn)
  • Session timeout and re-authentication for sensitive actions

Evidence

  • MFA enrollment and enforcement policy
  • Authentication configuration screenshots

Ask the vendor

  • Can we enforce MFA org-wide, and is WebAuthn supported?
  • Are session lifetimes and step-up policies configurable?

Monitoring and audit logging (CC7.2)

Identity and access events must be logged and monitored so anomalies can be detected.

CIAM controls

  • Centralized, tamper-evident audit logs of auth and admin events
  • Alerting on anomalous access
  • Log export to a SIEM

Evidence

  • Audit log samples with retention policy
  • SIEM integration / log streaming configuration

Ask the vendor

  • What identity events are logged, and for how long are they retained?
  • Can logs stream to our SIEM in near real time?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

Does SOC 2 require MFA?
The Trust Services Criteria do not name MFA explicitly, but auditors expect authentication controls proportional to risk, and in practice MFA for administrative and privileged access is treated as a baseline. A SOC 2 report will document how you meet CC6.1 logical access controls.
Is a vendor's SOC 2 enough for my own SOC 2?
No. A vendor's SOC 2 covers their controls, not yours. You still need to configure identity controls in your tenant (MFA enforcement, RBAC, logging) and evidence them. Use the vendor's report as a subservice-organization control in your own audit.

Source

AICPA SOC 2 / Trust Services Criteria

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.