Evidence automation coverage estimator
Tell us what you run. The estimate shows which evidence collects itself, which needs a routine, and whether a paid compliance platform would change the picture.
The estimate is based on a typical first SOC 2 control set of around 80 controls, grouped into areas. The percentages are estimates, not a guarantee of what an auditor accepts.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
How the estimate works
A typical first SOC 2 control set is split into areas with a rough control count: cloud configuration 20, logging and monitoring 10, access 12, change 8, vulnerabilities 6, endpoints 6, people and HR 8, and governance, vendors and incident response 10. Each tool you run makes part of an area collect evidence by itself. Governance and people controls never fully automate. The areas and their evidence are on evidence collection.
Why can evidence never be fully automated?
Some controls are decisions by people: approving a policy, reviewing access, assessing a vendor, running a tabletop. Tools can prompt and record them, but someone still has to do them.
Want the routine set up?
Firms in the network automate what can be automated and run the rest.
Get matched