Compliance Scanning

SOC 2 Type II
Compliance Scanning

SaaS vendors and service organizations need SOC 2 Type II reports to demonstrate security to customers and prospects. ComplianceLayer maps external scan findings to the Common Criteria (CC) trust service criteria your auditor evaluates.

Control Mapping

SOC 2 Trust Service Criteria Mapped to Scan Modules

The following Common Criteria (CC) controls from the AICPA Trust Service Criteria are verified through external scanning.

Control IDCriteriaScan ModuleWhat We Check
CC6.1Logical and Physical Access ControlsOpen Ports / SSLImplement logical access security measures. Detects exposed administrative ports (RDP, SSH), database services, and validates authentication endpoints.
CC6.2Secure Remote AccessOpen PortsControl remote access to system components. Identifies exposed remote access services (RDP 3389, VNC, Telnet) and administrative interfaces.
CC6.5Restrict Logical AccessSecurity HeadersRestrict logical access using Referrer-Policy, Permissions-Policy, and access control headers to prevent data leakage.
CC6.6Security Measures Against ThreatsSecurity Headers / PortsImplement measures to protect against threats. Validates HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and network exposure.
CC6.7Data Transmission RestrictionsSSL/TLS / EmailRestrict transmission and movement of data. Validates TLS configuration, HTTPS enforcement, SPF, DKIM, DMARC, and encryption strength.
CC6.8Prevent Unauthorized SoftwareSecurity HeadersPrevent and detect unauthorized software. Validates Content-Security-Policy for script injection prevention.
CC7.1Detect and Monitor AnomaliesAll ModulesMonitor system components for anomalies indicating malicious acts or system failures. ComplianceLayer continuously scans for configuration drift.
CC7.2Monitor for AnomaliesSSL/TLSMonitor system components and detect anomalies. Identifies expired certificates, configuration changes, and new exposures.
CC9.1Business ContinuityDNS / EmailIdentify and manage risks that could affect business continuity. Validates DNS configuration and email authentication chain integrity.
CC6.8Software Authorization ControlsSecurity HeadersRestrict installation and execution of unauthorized software via Content-Security-Policy and script integrity validation.

SOC 2 is an organizational audit framework. These are the technical controls relevant to SOC 2 that can be verified externally. Full SOC 2 compliance requires auditor review of policies, procedures, and organizational controls.

How It Works

SOC 2 Evidence Collection in 3 Steps

01

Enter your domain

Submit your production domain. ComplianceLayer scans the full external surface across 16 security modules.

02

Review CC mapping

Each finding maps to specific Common Criteria trust service criteria with pass, fail, or partial status.

03

Share with your auditor

Download the compliance report as supporting evidence for your SOC 2 Type II audit.

FAQ

Common questions

Does ComplianceLayer replace a SOC 2 audit?

No. SOC 2 is an organizational audit framework that requires a CPA firm to examine your controls over a period of time. ComplianceLayer provides automated evidence for the technical controls within SOC 2 trust service criteria — specifically the CC6 (logical access) and CC7 (monitoring) families.

Which SOC 2 trust service criteria does ComplianceLayer cover?

ComplianceLayer maps to Common Criteria (CC) controls, primarily CC6 (Logical and Physical Access Controls) and CC7 (System Operations). These cover encryption, access control, network security, and monitoring — the technical controls verifiable through external scanning.

Can I share ComplianceLayer reports with my SOC 2 auditor?

Yes. The compliance-mapped scan report provides documented evidence of your external security posture. Auditors can use it as supporting evidence for technical control testing, particularly for access control and data transmission criteria.

How does continuous scanning help with SOC 2 Type II?

SOC 2 Type II evaluates controls over a period (typically 6-12 months). Scheduled ComplianceLayer scans provide a continuous audit trail showing your security posture over time, demonstrating that controls are operating effectively throughout the audit period.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.