Scope SOC 2 to your company from eight questions
applicability_briefAnswer eight company setup questions to create a tailored brief showing what each SOC 2 Common Criterion means for your organization and which to prioritize.
Instructions
Answer eight questions about how your company is set up and get back, for each of the 33 SOC 2 Common Criteria, what satisfying it actually looks like for a company shaped like yours and which ones to deal with first. Fully local and deterministic; no account, no network call, no model. Call applicability_questions first to get the question list. IMPORTANT: this does not remove criteria from scope — all 33 apply to essentially every SOC 2 Security engagement. It tells you what each one means for you and what to prioritise.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| cloud | Yes | Where infrastructure runs | |
| premises | Yes | Physical premises or company-owned hardware | |
| timeline | Yes | Where the company is in the SOC 2 process | |
| workforce | Yes | Who does the work | |
| iacCoverage | Yes | How much infrastructure is defined as code | |
| customerData | Yes | What kind of customer data is handled | |
| changeProcess | Yes | Whether every production change goes through a reviewed pull request | |
| productionAccess | Yes | How many people can change production |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| answers | Yes | ||
| caveats | Yes | ||
| summary | Yes | ||
| controls | Yes | ||
| startHere | Yes | ||
| scopeNotes | Yes |