Kaamos
SOC 2

SOC 2 compliance automation.

Automation earns its place here more than almost anywhere else: a Type 2 report covers a period of months, and proving a control operated throughout it is exactly the work that decays by hand. What automation does not do is produce the report. A SOC 2 is an examination performed by a licensed CPA firm, and the opinion is the product. Everything you buy from a software vendor, including from us, is preparation for that examination.

Quoted, because we sell in this category.

Unlike ISO 27001, the sources that define SOC 2 are public, so there is no excuse for paraphrasing them. The middle quotation is the AICPA working-group chair describing the marketing pattern in this category. We are in this category. It seemed worth printing anyway.

What a tool can genuinely automate

Collection, correlation and keeping a record current across an observation period that runs for months. This is the half where software is not just convenient but close to necessary.

Collecting evidence continuously across the observation period
A Type 2 report covers months, not a day, so the auditor is asking whether a control operated throughout — not whether it was configured correctly the morning you were asked. Reading access reviews, logging, backup and change records from the systems themselves, every day, is the only honest way to answer that. Screenshots taken the week before fieldwork answer a different question.
Mapping your controls to the criteria2017 Trust Services Criteria (with revised points of focus, 2022)
The criteria are published and stable, and the common criteria overlap heavily with what an ISO 27001 Annex A programme already produces. Keeping one control mapped to every criterion it satisfies, across frameworks, is bookkeeping — and doing it by hand is why teams pay twice for the same evidence.
Producing complete populations for sampling
The auditor samples from a population — every new joiner, every production change, every access grant in the period — and an incomplete population invalidates the sample. Generating that list from the source system, rather than from somebody's memory of the period, is exactly the work software should be doing.
Catching exceptions while the period is still open
An access review missed in month two is a finding in month nine, and by then it cannot be fixed — the period is the period. Continuous checking turns a report-time surprise into a Tuesday.
Assembling the evidence the examination asks for
Requests arrive per criterion and the answer is a document plus the trail that connects it to a system. Producing that on request rather than reconstructing it is a packaging problem, and a solved one.

What stays with your auditor

Under ISO 27001 the uncomputable part is management judgement. Under SOC 2 several of these are things only a licensed firm is permitted to do, which is a harder line than judgement.

The examination and the opinionAICPA Statements on Standards for Attestation Engagements
A SOC 2 report is an examination performed by CPAs, and the deliverable is the practitioner's opinion. No platform issues one, and no platform shortens the part where a person has to form it. Software you buy is preparation for that examination, however the pricing page phrases it.
Keeping the auditor independent of the tooling
The firm forming the opinion has to be objective about the controls it is examining. That is a professional obligation on the CPA, not a feature, and it is the reason a vendor cannot both run your programme and assure it.
Choosing the criteria and the system boundary2017 Trust Services Criteria (with revised points of focus, 2022)
Security is common to every SOC 2. Whether availability, processing integrity, confidentiality or privacy also apply is a decision about what you sell and what you promised customers, and it changes the cost and length of the examination. Pick more than you need and you pay for it every year.
Writing the system description and management's assertion
Management describes the system and asserts that the description is accurate and the controls suitably designed. It is a statement your company makes and stands behind. A tool can draft around it and hold the evidence underneath it; it cannot be the one asserting.
Living through the observation period
A Type 1 speaks to design at a point in time; a Type 2 speaks to operating effectiveness across a period, and the period has to actually elapse. This is the one thing in compliance that no amount of money or software compresses.

How Kaamos handles the automatable half.

Connect your cloud, identity provider and code host, and Kaamos reads their state every day rather than on the week you remember to. For a Type 2 that matters more than it does for any point-in-time framework: the question is whether the control held for the whole period, and only a record kept across the whole period can answer it.

Because the common criteria overlap heavily with ISO 27001 Annex A, one piece of evidence usually answers to both. That is the argument for running them together rather than paying twice for the same access review.

The other half is not ours and never will be. Your CPA firm performs the examination and writes the opinion, you choose which criteria are in scope, you make the assertion, and the observation period elapses at the speed of time. We would rather say that on the page you are evaluating us from than in a footnote afterwards.