Framework reference / Independent controls reporting
SOC 2 Readiness Support
A SOC 2 examination evaluates controls at a service organization relevant to the Trust Services Criteria. The applicable criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Scope
Security is required; the other categories are selected according to the service and commitments in scope. A Type I report addresses control design at a point in time, while Type II also covers operating effectiveness over a period.
Core structure
Security
Protection against unauthorized access, disclosure, damage, and system compromise.
Availability
Systems remain available for operation and use as committed or agreed.
Processing Integrity
Processing is complete, valid, accurate, timely, and authorized.
Confidentiality
Information designated confidential is protected according to commitments.
Privacy
Personal information is collected, used, retained, disclosed, and disposed of appropriately.
Operational evidence examples
How ShadowCore uses this reference
Boundaries and claims
Only an independent, qualified CPA firm can perform the examination and issue a SOC 2 report.
ShadowCore does not provide an attestation, guarantee a clean report, or determine the final examination scope.
Official source: AICPA SOC Suite of ServicesPublic reference material for product design and readiness planning. It is not legal advice, certification, or an independent assessment.