SOC 2 Foundations Quick Start Guide - Core Tier Offering
Get Audit Ready in 5 Steps with Sensiba
Before You Begin
This guide is intended for customers using a Compliance Automation Platform (such as Vanta, Drata, Sprinto, or Scrut) and is designed to help you prepare for your audit efficiently and with confidence. This is applicable whether you're going through your first SOC 2 Type 1, or Type 2 with us.
1. Configuring your Systems & Audit Scope
One of the first steps towards audit readiness is ensuring your Compliance Automation Platform is configured correctly. This includes connecting your key systems and defining the scope of your audit.
Establishing your audit scope early helps ensure the correct systems, users, and resources are included, reducing unnecessary work and avoiding delays later in the audit process.
Where applicable, we recommend connecting the following systems to your Compliance Automation Platform:
- Cloud Providers (e.g. AWS, Azure, Google Cloud)
- Databases (eg. MongoDB Atlas)
- Version Control (e.g. GitHub, GitLab, Bitbucket)
- Identity Provider (IdP) (e.g. Microsoft Entra ID, Okta, Google Workspace)
- Mobile Device Management (MDM) (e.g. Kandji, Jamf, Intune)
✅ In-scope: Production systems, databases containing sensitive data, and any infrastructure processing customer information.
❌ Out-of-scope: Development, testing, and sandbox environments.
💡Tip: Always confirm that your in-scope inventory covers all production systems and sensitive data and nothing unnecessary.
2. Review Your Applicable Control Framework
Each Compliance Automation Platform includes a comprehensive library of default controls. However, not all of these controls are required for your SOC 2 audit with us.
Please note:
- Your audit only requires a subset of the default controls available within your platform.
- Approximately 50 controls are applicable to the Security, Availability, and Confidentiality Trust Services Criteria.
- While our control frameworks also include Processing Integrity and Privacy, these criteria are not included in your audit scope by default unless specifically agreed.
- Any controls or evidence that are not applicable to your audit can be safely excluded or descoped in accordance with the control framework provided below.
Please download the control framework for your Compliance Automation Platform:
📥 Please click the relevant link below to download the applicable control framework that applies to your specific platform:
-
Sensiba's Vanta SOC 2 Control Framework here.
-
Sensiba's Drata SOC 2 Control Framework here.
-
Sensiba's Sprinto SOC 2 Control Framework here.
-
Sensiba's Scrut SOC 2 Control Framework here.
3. Grant Auditor Access
Granting auditor access early allows our team to review your environment, provide guidance, identify any gaps, and help you become audit-ready as efficiently as possible.
Please follow the instructions below for your applicable Compliance Automation Platform:
- Vanta – How to Grant Auditor Access
- Drata – How to Grant Auditor Access
- Sprinto – How to Grant Auditor Access
- Scrut – How to Grant Auditor Access
Once auditor access has been granted, please notify your Customer Success Manager so we can support your audit preparation.
4. Complete the Scoping Task through Sensiba Workspace
Sensiba Workspace is our new internal audit tool that will be used to perform your audit hand in hand with your platform.
Once your Lead Auditor has been introduced, they will provide instructions and request a task through Sensiba Workspace for you to complete the 'General & SOC 2 Scoping Task'.
The scoping task will define the boundaries of your audit and forms the basis of your final report - It tells your auditor exactly which systems are in scope.
💡 For new Sensiba clients, the General & SOC 2 Scoping task must be completed before the auditor can start the audit, but is not required to complete prior to the handover from Customer Success Team.
5. Key Focus Areas to Get Your Platform Audit-Ready
To ensure a smooth and efficient audit, we recommend reviewing and configuring the following areas within your Compliance Automation Platform before your audit begins.
- Personnel in Scope
Ensure all in-scope personnel are correctly recorded within your platform. Remove or mark as out of scope any users who do not have access to critical systems or sensitive data (including contractors, where applicable). - Policy Management
Create or upload your information security policies, assign them to personnel, and ensure all required policy acknowledgements have been completed. - Risk Management
Maintain a current risk register by documenting identified risks, assigning owners, and recording mitigation plans and review dates. - Vendor Management
Add your critical third-party vendors, assign appropriate risk ratings, and complete vendor reviews where required by your risk management process. - Continuous Monitoring
Configure and review your platform's automated monitoring checks to ensure key controls are operating effectively and any identified issues are investigated and resolved. - Device Compliance
Integrate your device management solution (MDM) or endpoint monitoring agent to verify that in-scope devices meet your organization's security requirements. - Evidence Collection
Review any controls requiring manual evidence and ensure the appropriate documentation is uploaded before the audit commences. Address any failed tests or outstanding tasks where possible.
💡 Tip: Think of these areas as the readiness foundation the stronger they are, the smoother your audit will go.