SOC 2, explained simply
SOC 2 is not a law and there is no deadline. It is an attestation report an auditor issues about how your company handles customer data — and for most B2B software companies it arrives as a question from a buyer rather than a regulator.
- Standard
- AICPA Trust Services Criteria (TSC 2017, rev. 2022)
- Version
- TSC 2017 with 2022 revised points of focus
- Jurisdiction
- US / global (SOC 2)
- Catalogue last verified
- 2026-07-15
Who asks you for it
Enterprise buyers, procurement teams and security reviewers — usually at the moment a deal is close to signing. If you sell software to larger companies, expect the question. The Security category (the Common Criteria) is in every SOC 2 report; Availability, Processing Integrity, Confidentiality and Privacy are added only when they are in scope for your service.
What is actually in it
Tawsik tracks every requirement in the published catalogue, grouped by its official numbering.
61requirements tracked
- CC · 33
- P · 18
- PI · 5
- A · 3
- C · 2
What evidence can prove — and what it can’t
We would rather tell you this up front than let a dashboard imply more certainty than it has.
Where Tawsik fits
Tawsik does not issue SOC 2 reports — only a licensed CPA firm can. What Tawsik does is get you ready and keep you ready: it maps your evidence to the criteria, shows you what is missing, and reuses the same evidence across every other framework you are asked about, so you gather each proof once instead of once per questionnaire.
Tawsik is not a certification body or an auditor.
One set of evidence, every framework
Tawsik maps one canonical control to every framework that asks for it, so a proof you gather once counts everywhere it applies.
See where you stand
Start with the free EU AI Act check — no account, no email. Your workspace covers the rest.
Tawsik guides you toward compliance. It isn’t legal advice.