Skip to content
English
  • There are no suggestions because the search field is empty.

SOC 2 Foundations Quick Start Guide - Core Tier Offering

Get Audit Ready in 5 Steps with Sensiba

Before You Begin

This guide is intended for customers using a Compliance Automation Platform (such as Vanta, Drata, Sprinto, or Scrut) and is designed to help you prepare for your audit efficiently and with confidence. This is applicable whether you're going through your first SOC 2 Type 1, or Type 2 with us.

1. Configuring your Systems & Audit Scope

One of the first steps towards audit readiness is ensuring your Compliance Automation Platform is configured correctly. This includes connecting your key systems and defining the scope of your audit.

Establishing your audit scope early helps ensure the correct systems, users, and resources are included, reducing unnecessary work and avoiding delays later in the audit process.

Where applicable, we recommend connecting the following systems to your Compliance Automation Platform:

  • Cloud Providers (e.g. AWS, Azure, Google Cloud)
  • Databases (eg. MongoDB Atlas)
  • Version Control (e.g. GitHub, GitLab, Bitbucket)
  • Identity Provider (IdP) (e.g. Microsoft Entra ID, Okta, Google Workspace)
  • Mobile Device Management (MDM) (e.g. Kandji, Jamf, Intune)

✅ In-scope: Production systems, databases containing sensitive data, and any infrastructure processing customer information.

❌ Out-of-scope: Development, testing, and sandbox environments.

💡Tip: Always confirm that your in-scope inventory covers all production systems and sensitive data and nothing unnecessary.


2. Review Your Applicable Control Framework

Each Compliance Automation Platform includes a comprehensive library of default controls. However, not all of these controls are required for your SOC 2 audit with us.

Please note:

  • Your audit only requires a subset of the default controls available within your platform.
  • Approximately 50 controls are applicable to the Security, Availability, and Confidentiality Trust Services Criteria.
  • While our control frameworks also include Processing Integrity and Privacy, these criteria are not included in your audit scope by default unless specifically agreed.
  • Any controls or evidence that are not applicable to your audit can be safely excluded or descoped in accordance with the control framework provided below.

Please download the control framework for your Compliance Automation Platform:

📥 Please click the relevant link below to download the applicable control framework that applies to your specific platform:


3. Grant Auditor Access

Granting auditor access early allows our team to review your environment, provide guidance, identify any gaps, and help you become audit-ready as efficiently as possible.

Please follow the instructions below for your applicable Compliance Automation Platform:

Once auditor access has been granted, please notify your Customer Success Manager so we can support your audit preparation.


4. Complete the Scoping Task through Sensiba Workspace

Sensiba Workspace is our new internal audit tool that will be used to perform your audit hand in hand with your platform.

Once your Lead Auditor has been introduced, they will provide instructions and request a task through Sensiba Workspace for you to complete the 'General & SOC 2 Scoping Task'.

The scoping task will define the boundaries of your audit and forms the basis of your final report - It tells your auditor exactly which systems are in scope.

 

💡 For new Sensiba clients, the General & SOC 2 Scoping task must be completed before the auditor can start the audit, but is not required to complete prior to the handover from Customer Success Team.


5. Key Focus Areas to Get Your Platform Audit-Ready

To ensure a smooth and efficient audit, we recommend reviewing and configuring the following areas within your Compliance Automation Platform before your audit begins.

  • Personnel in Scope
    Ensure all in-scope personnel are correctly recorded within your platform. Remove or mark as out of scope any users who do not have access to critical systems or sensitive data (including contractors, where applicable).
  • Policy Management
    Create or upload your information security policies, assign them to personnel, and ensure all required policy acknowledgements have been completed.
  • Risk Management
    Maintain a current risk register by documenting identified risks, assigning owners, and recording mitigation plans and review dates.
  • Vendor Management
    Add your critical third-party vendors, assign appropriate risk ratings, and complete vendor reviews where required by your risk management process.
  • Continuous Monitoring
    Configure and review your platform's automated monitoring checks to ensure key controls are operating effectively and any identified issues are investigated and resolved.
  • Device Compliance
    Integrate your device management solution (MDM) or endpoint monitoring agent to verify that in-scope devices meet your organization's security requirements.
  • Evidence Collection
    Review any controls requiring manual evidence and ensure the appropriate documentation is uploaded before the audit commences. Address any failed tests or outstanding tasks where possible.

 

💡 Tip: Think of these areas as the readiness foundation the stronger they are, the smoother your audit will go.