// Information Security
SOC 2 Type II Compliance Software
Service Organisation Controls 2. Audit framework for service providers handling customer data — Trust Services Criteria.
Framework at a glance
Short name
SOC 2
Version
2017
Category
Information Security
Controls
61
What SOC 2 covers
61 controls across 5 domains — every one tracked, owned and evidenced in Cyber Horizon.
Security
33 controls- CC1.1 Integrity and ethical values
- CC1.2 Board independence and oversight
- CC1.3 Structures, reporting lines and authorities
- CC1.4 Commitment to competence
- CC1.5 Accountability for internal control
Availability
3 controls- A1.1 Capacity management
- A1.2 Environmental protections, backup and recovery infrastructure
- A1.3 Recovery plan testing
Confidentiality
2 controls- C1.1 Identification and maintenance of confidential information
- C1.2 Disposal of confidential information
Processing Integrity
5 controls- PI1.1 Processing information and specifications
- PI1.2 System input controls
- PI1.3 System processing controls
- PI1.4 System output controls
- PI1.5 Storage of inputs, in-process items and outputs
Privacy
18 controls- P1.1 Privacy notice
- P2.1 Choice and consent
- P3.1 Collection consistent with objectives
- P3.2 Explicit consent
- P4.1 Limitation of use
How Cyber Horizon automates SOC 2
Every SOC 2 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is SOC 2 Type II?
Service Organisation Controls 2. Audit framework for service providers handling customer data — Trust Services Criteria.
How many controls does SOC 2 Type II have?
SOC 2 Type II (2017) has 61 controls in Cyber Horizon's catalogue, organised across 5 domains.
How does Cyber Horizon help with SOC 2 Type II?
Cyber Horizon maps SOC 2 Type II into a shared control library alongside every other framework you run, so evidence collected once counts towards SOC 2 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Information Security frameworks
See SOC 2 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of SOC 2 in Cyber Horizon.