SOC 2 control catalog
controlsFetch the SOC 2 Security catalog of 33 Common Criteria. Omit controlId for the full list or pass a specific ID (CC1.1–CC9.2) to examine that criterion's IaC evidence capability.
Instructions
Returns the SOC 2 control catalog this server evaluates against. Pass controlId for
one control; omit it for all.
Scope is the SOC 2 Security category, which is all 33 Common Criteria (CC1.1-CC9.2). The optional A / C / PI / P categories are NOT covered.
An IaC scan is the primary evidence source for only 3 of the 33 and partially informs 8;
the remaining 22 need documents, people or live cloud state. Each control reports what a
scan can and cannot evidence for it via its iac capability and iacNote.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| controlId | No | A single control to return. Omit for the full catalog. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| controls | Yes | ||
| frameworkScope | Yes | ||
| supportedControlIds | Yes |