Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does ShipReady Metrics support SOC 2 evidence?

Last verified

It collects evidence continuously, records a human met verdict per control, crosswalks SOC 2 to canonical controls by criteria series reference, holds policies, ingests connector findings, and shares a scoped reviewer view. It prepares evidence; it does not issue the report — only a licensed CPA firm does.

How ShipReady Metrics supports SOC 2 evidence, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.

The boundary, stated first

Audience: an evaluator, compliance owner, or CISO deciding whether this product helps with a SOC 2 examination. Everything described here is shipped capability. There is no roadmap language on this page, and no claim about what a future version might do.

This product prepares and organises evidence. It does not perform the examination, does not sample, does not decide whether evidence is sufficient, does not form or sign an opinion, and does not issue a SOC 2 report. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor. Readiness in this product is not an attestation opinion, and a view where every control is green is your own internal assessment, not assurance.

SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report, and nothing in this product creates or discharges an obligation. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate, and no dashboard here is one. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, which is why continuous capture is the feature that matters most. Last verified 10 September 2026. Not legal advice.

Capability to criteria series

Mapping, not marketing. The right-hand column is what the product does not do for that area, because that is the more useful half of the table. Criteria series references only — the Trust Services Criteria are proprietary AICPA material and their text is never reproduced here.

Shipped capability mapped to criteria series references (paraphrase; the criterion text is proprietary AICPA material and is not reproduced; not an attestation opinion)
CapabilitySeries it helps evidenceWhat it doesWhat it does not do
Evidence collectionCC1–CC9, and optional categories where you collect for them.Captures artefacts with their own timestamps as controls run, so a period is evidenced rather than reconstructed.Does not decide sufficiency, does not sample, and does not guarantee a practitioner accepts a given artefact.
Evidence review with the met-verdict overlayCC4 primarily, and any series where a control is judged met or not.Records a named human's judgement that specific evidence supports a control, with who decided and when.Is an internal judgement, never an audit conclusion and never an opinion.
24-framework crosswalkCC1–CC9 mapped to this product's canonical controls, alongside 23 other frameworks.Shows where a control already evidenced for another framework relates to a SOC 2 criteria series, cited by reference with a crosswalk-density honesty layer.Does not reproduce Trust Services Criteria text, and mapped coverage is not a count of criteria met.
Obligation mapScoping, ahead of any series.Records which frameworks the organisation marked in-scope, including the bundled framework key soc2.Marking soc2 in-scope is not a determination that a buyer requires SOC 2 and is not an examination scope decision.
Policies libraryCC1, CC2, and wherever a documented policy is the control.Holds policy documents and acknowledgements with dates.Does not write your policies for you, and a stored policy is not evidence that anybody follows it.
Connector-sourced evidenceCC7 and CC8.Ingests dependency findings, code-scanning results, and secret-scanning results continuously with their own timestamps.Does not cover controls with no connector, and does not remediate anything.
ShipReady Passport and the auditor share tokenCross-cutting.Hands a reviewer or prospect a scoped view of posture and evidence without giving them an account.Is not a SOC 2 report, not a bridge letter, and not assurance of any kind.
Cyber risk registerCC3, CC4, CC9.Tracks risks and remediation items with owners and dates.Is not a risk assessment performed on your behalf, and is not an incident filing.
Engineering delivery metrics and per-committer viewsNone directly.Engineering-governance signal for your own management purposes.Not attestation evidence, not a criterion, and should not be presented to a practitioner as a control.

What this product does not touch

An evaluator's most useful question is where the tool stops. These gaps are real and stating them is cheaper than being found out.

  • The examination itself, in every part: planning, walkthroughs, sampling, testing, and the opinion. Attestation-standard requirement — that work belongs to the licensed CPA firm.
  • The system description and management's assertion. You write and sign both; no tool can assert on your behalf.
  • Physical security and facilities, where those are the cloud provider's and appear via their own report.
  • Human-performed controls with no digital trace — a conversation, an undocumented approval, a review nobody recorded.
  • Legal determinations of any kind, including whether a regulatory regime applies to you.
  • Auditor selection. We name no firms and rank nobody.
  • Any claim of certification. There is no SOC 2 certificate to issue, and this product issues nothing.

How it fits the lifecycle

Phase by phase, using the lifecycle from the how-to-get guide on this site. Labelled by kind of text so nothing here reads as a requirement.

Product fit by lifecycle phase (SRM recommendation and best practice; not an attestation requirement; not an opinion)
PhaseWhat helpsKind of textBoundary
ScopeObligation map records the soc2 mark; the crosswalk shows overlap with frameworks already in play.SRM recommendation.You still draw the boundary and write the description.
Gap assessmentThe starter control-set for soc2 plus evidence review shows which controls have nothing behind them.Best practice — a gap assessment is not required by any attestation standard.The starter control-set is illustrative, to be tailored by a compliance owner. It is not the criteria.
RemediatePolicies library for missing documents; cyber risk register for tracked remediation; connector findings for engineering gaps.SRM recommendation.The product does not implement controls.
Engage a CPA firmNothing. This is vendor-neutral territory and we take no part in it.Attestation-standard requirement that a licensed practitioner be engaged.We name no firms, rank nobody, and do not resell examinations.
Observation periodContinuous evidence collection with real timestamps; met verdicts recorded as you go.Best practice — the period requirement is the standard's; continuous capture is the practice.Does not shorten the period, which is a scoping decision with your firm.
FieldworkEvidence retrieval for the request list; Passport share for a scoped reviewer view.SRM recommendation.Populations must still be producible from your systems of record, and sufficiency is the practitioner's judgement.
ReportNothing. The firm drafts and issues.Attestation-standard requirement — the opinion is the practitioner's.This product does not issue a SOC 2 report and does not replace a licensed CPA examination.

Kinds of text on this page

Different sentences here carry different weight. On a product page the labels matter more, not less.

How to read the claims on this page (not a ranking; not legal advice; last verified 10 September 2026)
Kind of textWhat it meansWhat it is not
Attestation-standard requirementSSAE 18 — AT-C sections 105 and 205 — including that only the practitioner forms and issues the opinion.Not a statute, and not something a product can satisfy on your behalf.
Trust Services Criteria referenceA pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100.Not the criterion text. The Trust Services Criteria are proprietary AICPA material; the crosswalk cites references only.
Best practicePractices this product supports, such as continuous capture and gap assessment.Not required by any attestation standard. Skipping it is not an exception.
Market observationWhat teams and firms are commonly observed to do.Not a rule, and not a promise about YOUR engagement.
SRM recommendationSomething this product suggests doing. Most of this page is in this category.Not a legal requirement, not an attestation requirement, and not an audit opinion.

What to do now

If you are evaluating, evaluate against the boundary rather than the feature list. These are the questions that separate preparation from assurance.

  • Confirm who your attestor will be, independently of any tooling decision. Only a licensed CPA firm can perform the examination and issue the report.
  • Ask which of your in-scope controls have a connector and which will need manual evidence. The manual set is the real work.
  • Ask your CPA firm what evidence format they want before building around a different one.
  • Mark soc2 on the obligation map only as a record of intent, and do not treat the mark as a scope decision.
  • Use the crosswalk to find overlap with frameworks you already evidence, then verify each mapping yourself — a crosswalk is an illustrative mapping, not a determination.
  • Do not show a prospect a green readiness view as though it were assurance. Share a scoped Passport view and say plainly what it is.
  • Do not wait for a tool to produce your system description or your management assertion. Those are yours.

Checklist

An evaluation checklist for this page's subject, labelled by kind of text.

  • Licensed CPA firm identified separately from any tooling choice? Attestation-standard requirement.
  • Connector coverage mapped against in-scope controls, with the manual remainder listed? SRM recommendation.
  • Evidence format agreed with the firm? Market observation — prevents rework.
  • Crosswalk mappings verified by a human rather than assumed? Trust Services Criteria reference — mapped coverage is not criteria met.
  • System description and management assertion owned by named humans? Attestation-standard requirement.
  • Everyone clear that readiness here is not an opinion? Attestation-standard requirement.
  • Nobody describing this product as issuing, or being, a SOC 2 report? Non-negotiable.

Where this shows up in ShipReady Metrics

The bundled framework key soc2 is customer-visible. Its version label references the 2017 Trust Services Criteria with the 2022 revised points of focus. It is not restricted to internal testers. Its control-set is a starter subset — an illustrative readiness mapping to be tailored by a compliance owner, not the criteria and not an audit programme.

If you already have a session: evidence collection, evidence review with the met-verdict overlay, the policies library, the 24-framework crosswalk with its crosswalk-density honesty layer, connector-sourced evidence from dependency, code-scanning, and secret-scanning ingest, ShipReady Passport with the auditor share token, the obligation map, and the cyber risk register under the security area are the surfaces this page describes. Every one of them is preparation.

Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL, and there is no published SOC 2 report for this product on this page.

Primary sources (last verified 10 September 2026)

The attestor boundary comes from the AICPA attestation standards. Product statements describe shipped capability only.

AICPA attestation standards SSAE 18, AT-C section 105 and AT-C section 205, which reserve the opinion to the practitioner. AICPA Trust Services Criteria, TSP section 100 — 2017 criteria with the 2022 revised points of focus, organised into the common criteria series CC1 through CC9 plus optional categories. Proprietary AICPA material: cited by reference and paraphrased, never reproduced. AICPA SOC 2 guidance for service organisations. ShipReady Metrics product documentation for the capabilities named. These are not a complete list, and none of them is legal advice.

The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 readiness checklist template on this site is live. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.

Frequently asked questions