SOC 2 Type II
Compliance Scanning
SaaS vendors and service organizations need SOC 2 Type II reports to demonstrate security to customers and prospects. ComplianceLayer maps external scan findings to the Common Criteria (CC) trust service criteria your auditor evaluates.
SOC 2 Trust Service Criteria Mapped to Scan Modules
The following Common Criteria (CC) controls from the AICPA Trust Service Criteria are verified through external scanning.
| Control ID | Criteria | Scan Module | What We Check |
|---|---|---|---|
| CC6.1 | Logical and Physical Access Controls | Open Ports / SSL | Implement logical access security measures. Detects exposed administrative ports (RDP, SSH), database services, and validates authentication endpoints. |
| CC6.2 | Secure Remote Access | Open Ports | Control remote access to system components. Identifies exposed remote access services (RDP 3389, VNC, Telnet) and administrative interfaces. |
| CC6.5 | Restrict Logical Access | Security Headers | Restrict logical access using Referrer-Policy, Permissions-Policy, and access control headers to prevent data leakage. |
| CC6.6 | Security Measures Against Threats | Security Headers / Ports | Implement measures to protect against threats. Validates HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and network exposure. |
| CC6.7 | Data Transmission Restrictions | SSL/TLS / Email | Restrict transmission and movement of data. Validates TLS configuration, HTTPS enforcement, SPF, DKIM, DMARC, and encryption strength. |
| CC6.8 | Prevent Unauthorized Software | Security Headers | Prevent and detect unauthorized software. Validates Content-Security-Policy for script injection prevention. |
| CC7.1 | Detect and Monitor Anomalies | All Modules | Monitor system components for anomalies indicating malicious acts or system failures. ComplianceLayer continuously scans for configuration drift. |
| CC7.2 | Monitor for Anomalies | SSL/TLS | Monitor system components and detect anomalies. Identifies expired certificates, configuration changes, and new exposures. |
| CC9.1 | Business Continuity | DNS / Email | Identify and manage risks that could affect business continuity. Validates DNS configuration and email authentication chain integrity. |
| CC6.8 | Software Authorization Controls | Security Headers | Restrict installation and execution of unauthorized software via Content-Security-Policy and script integrity validation. |
SOC 2 is an organizational audit framework. These are the technical controls relevant to SOC 2 that can be verified externally. Full SOC 2 compliance requires auditor review of policies, procedures, and organizational controls.
SOC 2 Evidence Collection in 3 Steps
Enter your domain
Submit your production domain. ComplianceLayer scans the full external surface across 16 security modules.
Review CC mapping
Each finding maps to specific Common Criteria trust service criteria with pass, fail, or partial status.
Share with your auditor
Download the compliance report as supporting evidence for your SOC 2 Type II audit.
Common questions
Does ComplianceLayer replace a SOC 2 audit?
No. SOC 2 is an organizational audit framework that requires a CPA firm to examine your controls over a period of time. ComplianceLayer provides automated evidence for the technical controls within SOC 2 trust service criteria — specifically the CC6 (logical access) and CC7 (monitoring) families.
Which SOC 2 trust service criteria does ComplianceLayer cover?
ComplianceLayer maps to Common Criteria (CC) controls, primarily CC6 (Logical and Physical Access Controls) and CC7 (System Operations). These cover encryption, access control, network security, and monitoring — the technical controls verifiable through external scanning.
Can I share ComplianceLayer reports with my SOC 2 auditor?
Yes. The compliance-mapped scan report provides documented evidence of your external security posture. Auditors can use it as supporting evidence for technical control testing, particularly for access control and data transmission criteria.
How does continuous scanning help with SOC 2 Type II?
SOC 2 Type II evaluates controls over a period (typically 6-12 months). Scheduled ComplianceLayer scans provide a continuous audit trail showing your security posture over time, demonstrating that controls are operating effectively throughout the audit period.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.