CloudCompliance

Evidence automation coverage estimator

Tell us what you run. The estimate shows which evidence collects itself, which needs a routine, and whether a paid compliance platform would change the picture.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

The estimate is based on a typical first SOC 2 control set of around 80 controls, grouped into areas. The percentages are estimates, not a guarantee of what an auditor accepts.

Which cloud providers run production?
Which native services are switched on and keeping history?
What else is in place?
How will you organize evidence?

How many people work at the company?

How the estimate works

A typical first SOC 2 control set is split into areas with a rough control count: cloud configuration 20, logging and monitoring 10, access 12, change 8, vulnerabilities 6, endpoints 6, people and HR 8, and governance, vendors and incident response 10. Each tool you run makes part of an area collect evidence by itself. Governance and people controls never fully automate. The areas and their evidence are on evidence collection.

Why can evidence never be fully automated?

Some controls are decisions by people: approving a policy, reviewing access, assessing a vendor, running a tabletop. Tools can prompt and record them, but someone still has to do them.

Want the routine set up?

Firms in the network automate what can be automated and run the rest.

Get matched