SOC 2 compliance automation.
Automation earns its place here more than almost anywhere else: a Type 2 report covers a period of months, and proving a control operated throughout it is exactly the work that decays by hand. What automation does not do is produce the report. A SOC 2 is an examination performed by a licensed CPA firm, and the opinion is the product. Everything you buy from a software vendor, including from us, is preparation for that examination.
Quoted, because we sell in this category.
Unlike ISO 27001, the sources that define SOC 2 are public, so there is no excuse for paraphrasing them. The middle quotation is the AICPA working-group chair describing the marketing pattern in this category. We are in this category. It seemed worth printing anyway.
Established in 2011, SOC reports are examinations performed by CPAs in accordance with the AICPA’s Statements on Standards for Attestation Engagements to evaluate the controls over customer data that service organizations such as cloud providers or payroll processors have in place.
Journal of Accountancy, “Promises of ‘fast and easy’ threaten SOC credibility”, February 2026 An examination performed by CPAs. That is the whole distinction between what software prepares and what a firm delivers, stated by the institute that defines the report.
[SOC] professionals are seeing indications that ‘fast and easy’ may come at the expense of quality and objectivity,
Sean Linton, CPA/CITP, chair of the AICPA Assurance Services Executive Committee’s SOC 2 Working Group, in the Journal of Accountancy, February 2026 The chair of the AICPA working group that maintains SOC 2 naming the marketing pattern directly. We sell software in this category, so it is worth being plain: speed is a property of the preparation, never of the opinion.
The 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus — 2022) (2017 TSC) presents control criteria established by the AICPA’s Assurance Services Executive Committee (ASEC) for use in attestation or consulting engagements
AICPA & CIMA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022) The five categories, named by the body that sets them. Security applies to every SOC 2; the other four are a scoping decision you make before the examination starts.
What a tool can genuinely automate
Collection, correlation and keeping a record current across an observation period that runs for months. This is the half where software is not just convenient but close to necessary.
- Collecting evidence continuously across the observation period
- A Type 2 report covers months, not a day, so the auditor is asking whether a control operated throughout — not whether it was configured correctly the morning you were asked. Reading access reviews, logging, backup and change records from the systems themselves, every day, is the only honest way to answer that. Screenshots taken the week before fieldwork answer a different question.
- Mapping your controls to the criteria2017 Trust Services Criteria (with revised points of focus, 2022)
- The criteria are published and stable, and the common criteria overlap heavily with what an ISO 27001 Annex A programme already produces. Keeping one control mapped to every criterion it satisfies, across frameworks, is bookkeeping — and doing it by hand is why teams pay twice for the same evidence.
- Producing complete populations for sampling
- The auditor samples from a population — every new joiner, every production change, every access grant in the period — and an incomplete population invalidates the sample. Generating that list from the source system, rather than from somebody's memory of the period, is exactly the work software should be doing.
- Catching exceptions while the period is still open
- An access review missed in month two is a finding in month nine, and by then it cannot be fixed — the period is the period. Continuous checking turns a report-time surprise into a Tuesday.
- Assembling the evidence the examination asks for
- Requests arrive per criterion and the answer is a document plus the trail that connects it to a system. Producing that on request rather than reconstructing it is a packaging problem, and a solved one.
What stays with your auditor
Under ISO 27001 the uncomputable part is management judgement. Under SOC 2 several of these are things only a licensed firm is permitted to do, which is a harder line than judgement.
- The examination and the opinionAICPA Statements on Standards for Attestation Engagements
- A SOC 2 report is an examination performed by CPAs, and the deliverable is the practitioner's opinion. No platform issues one, and no platform shortens the part where a person has to form it. Software you buy is preparation for that examination, however the pricing page phrases it.
- Keeping the auditor independent of the tooling
- The firm forming the opinion has to be objective about the controls it is examining. That is a professional obligation on the CPA, not a feature, and it is the reason a vendor cannot both run your programme and assure it.
- Choosing the criteria and the system boundary2017 Trust Services Criteria (with revised points of focus, 2022)
- Security is common to every SOC 2. Whether availability, processing integrity, confidentiality or privacy also apply is a decision about what you sell and what you promised customers, and it changes the cost and length of the examination. Pick more than you need and you pay for it every year.
- Writing the system description and management's assertion
- Management describes the system and asserts that the description is accurate and the controls suitably designed. It is a statement your company makes and stands behind. A tool can draft around it and hold the evidence underneath it; it cannot be the one asserting.
- Living through the observation period
- A Type 1 speaks to design at a point in time; a Type 2 speaks to operating effectiveness across a period, and the period has to actually elapse. This is the one thing in compliance that no amount of money or software compresses.
How Kaamos handles the automatable half.
Connect your cloud, identity provider and code host, and Kaamos reads their state every day rather than on the week you remember to. For a Type 2 that matters more than it does for any point-in-time framework: the question is whether the control held for the whole period, and only a record kept across the whole period can answer it.
Because the common criteria overlap heavily with ISO 27001 Annex A, one piece of evidence usually answers to both. That is the argument for running them together rather than paying twice for the same access review.
The other half is not ours and never will be. Your CPA firm performs the examination and writes the opinion, you choose which criteria are in scope, you make the assertion, and the observation period elapses at the speed of time. We would rather say that on the page you are evaluating us from than in a footnote afterwards.
Sources
- AICPA & CIMA, System and Organization Controls: SOC Suite of Services
- 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
- Journal of Accountancy, “Promises of ‘fast and easy’ threaten SOC credibility”
- Journal of Accountancy, “AICPA guides peer reviewers to address SOC 2 risks”
- AICPA & CIMA, Trust Services Criteria and information for management of a service organization
The Trust Services Criteria and the AICPA’s description of the SOC suite are published without charge, so every quotation above can be checked at its link. Last reviewed .