Community
Free
Self-hosted. No user limit, no time limit.
DownloadThere is no SOC 2 certificate and no pass mark. A licensed CPA firm writes an opinion on whether your controls were designed well and, in a Type II, whether they actually ran for months. That is a record-keeping problem before it is a security one.
Only Security is mandatory. Each category you add widens the report, the control set and the audit - so pick the ones your customers actually ask about.
Both are the same criteria. They differ in what the auditor is allowed to say about them, and that difference is the whole reason a GRC tool matters here.
An opinion that the controls were suitably designed as of a single date. Nothing is said about whether they ran.
An opinion that the controls were designed well and operated effectively across a period, commonly three to twelve months. This is the one customers ask for.
Between two reports a bridge letter covers the gap. It is your statement, not the auditor’s opinion.
CC1 to CC5 follow the COSO framework - the governance half. CC6 to CC9 are the operational half. The first column is the criterion, the second is what eramba holds for it.
Under each criterion sit the points of focus. They are considerations the auditor weighs, not a checklist you must satisfy line by line - the AICPA says so explicitly, and treating them as requirements is the most common way a first SOC 2 doubles in size.
Section 3 of a SOC 2 report is your description of the system and its controls; section 4 is the auditor placing each criterion against the controls you claim satisfy it, and the tests they ran.
That mapping is a report in eramba, not a spreadsheet somebody maintains. Import the criteria as a CSV like any other framework, and each one carries its strategy, its owner, its linked policies and internal controls, and its status.
The opinion is signed by a licensed CPA firm. Nobody else can issue it, and no software can shorten the window a Type II covers - if your customers want six months of evidence, that is six months.
What software decides is whether those six months exist as a record when the auditor asks. A control with an owner and a testing interval leaves a trail on its own; the same control kept in somebody’s calendar does not.
eramba is also not your auditor’s workpapers and not a monitoring agent. It will not watch your cloud accounts or collect a screenshot for you unless you point an automated test at the system that knows.
Your system, its boundaries and the controls you claim - written, approved and versioned.
Each control tested on its schedule across the whole window, with results kept.
Where a control did not run, said plainly, with the corrective action attached.
Subservice organisations, their own reports, and what you carved out.
The Community edition is free and self-hosted. Import the Trust Services Criteria as a CSV the same way every other framework is imported, and see what a year of evidence would look like before you sign with an audit firm.
The management system most SOC 2 programmes are run on, clause by clause.
See the pageFramework pageThe controls that end up satisfying CC5 to CC8.
See the pageUse caseThe method behind CC3 and CC9.
See the pageUse caseThe six steps that apply to every framework you import.
See the pageFlat annual price. Unlimited users, unlimited frameworks, every module included. Your bill does not grow with your team.
Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.
Free
Self-hosted. No user limit, no time limit.
Downloadfrom 2500€/year
Runs on your infrastructure, with support and updates.
See pricingfrom 5000€/year
Hosted and operated by eramba, in the EU.
See pricingA practitioner answers, not a sales sequence.