Compyl
Framework · SOC 2AICPA · Type I & II

SOC 2 compliance that holds between audits.

Compyl’s SOC 2 compliance software collects your evidence automatically, monitors every Trust Services Criteria control in real time, and keeps you continuously audit-ready, so a Type II is something you maintain, not something you scramble for.

Last reviewed September 2026 by the Compyl GRC team
5 Trust Services Criteria125+ integrationsContinuous evidence
SOC 2 · Type II readinessObservation window · day 148 of 365
92%ready
Evidence collected96%
Controls passing71 / 74
Evidence Health94
SecurityAvailabilityConfidentialityProcessing Integrity · 1 driftingPrivacy · out of scope
CC6.1 · Logical accessMFA enforced on all IAM users · Okta, AWS · refreshed 12 min ago
Passing
PI1.4 · Processing completenessBatch reconciliation job missed 2 runs · task assigned to Data Eng
Drift → task
Auditor evidence pack · current as of todayExport on demand
The problem

Point-in-time SOC 2 breaks the moment the audit ends

A clean report proves your controls worked on the days they were sampled. The risk lives in everything that happens between audits, when evidence goes stale and controls quietly drift.

The evidence scramble

Weeks of chasing screenshots, logs, and exports across teams every audit cycle, manual, error-prone, and impossible to scale.

Silent control drift

A revoked-access SLA slips, a config changes, an owner leaves. Controls fail quietly for months with no one watching until the next audit.

Growth raises the bar

More systems, more people, more frameworks. Each audit gets harder, and bolting on headcount to keep up doesn’t scale.

How it works

One continuous loop, from connected systems to audit-ready

Compyl runs SOC 2 as an always-on cycle, not a pre-audit project. Each stage feeds the next and never stops.

01

Connect

Integrate cloud, identity, code, endpoint, and HR systems.

02

Collect evidence

Pull audit evidence automatically, in real time.

03

Map to criteria

Link every control and artifact to the right TSC.

04

Monitor

Watch controls continuously and flag drift early.

05

Stay audit-ready

Hand auditors a current evidence pack on demand.

The framework

Coverage across all five Trust Services Criteria

SOC 2 is built on five Trust Services Criteria. Security is required in every report; the rest are scoped to your services. Compyl maps controls and evidence to each one.

Security

Required
CC1–CC9

The Common Criteria: protecting systems and data against unauthorized access and disclosure.

In every SOC 2 report

Availability

Scoped
A1

Keeping systems and data accessible to authorized users to meet uptime and SLA commitments.

Common for SaaS & hosting

Processing Integrity

Scoped
PI1

Ensuring system processing is complete, valid, accurate, timely, and authorized.

Fintech & payments

Confidentiality

Scoped
C1

Restricting and protecting information designated as confidential throughout its lifecycle.

Common for B2B SaaS

Privacy

Scoped
P1–P8

Governing how personal information is collected, used, retained, disclosed, and disposed of.

When personal data is in scope
Automated evidence

Stop collecting SOC 2 evidence by hand

The biggest cost of SOC 2 isn’t the audit fee, it’s the weeks your team spends gathering proof. Compyl collects it continuously from the systems you already run, so the evidence is always current and always mapped.

  • Pull evidence automatically from cloud, identity, code, and endpoint tools
  • Every artifact mapped to the Trust Services Criteria it supports
  • No more screenshots, spreadsheets, or last-minute requests
  • Export a complete, auditor-ready evidence pack on demand
Evidence · collected automatically1,284 artifacts · live
AWS · IAM, CloudTrail, S3412 artifacts · mapped to CC6.x, CC7.x
Synced 2m
Okta · users, MFA, groups218 artifacts · mapped to CC6.1–CC6.3
Synced 5m
GitHub · branch protection, reviews163 artifacts · mapped to CC8.1
Synced 9m
Rippling · onboarding, offboarding97 artifacts · mapped to CC1.4, CC6.2
Synced 1h
No screenshots, no spreadsheets, no last-minute requestsAuditor-ready pack
Evidence Health · New in 26.2

Know your evidence is audit-ready, automatically

Collecting evidence is only half the battle; stale or incomplete proof is where audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces weeks before an audit, not during it.

  • Every artifact scored on relevance, freshness, and completeness
  • An AI summary spells out exactly what’s missing and why
  • Re-scores automatically whenever the underlying evidence changes
  • Gaps surface with time to fix, not during fieldwork
Evidence HealthNew in 26.2 · re-scores on change
ArtifactAccess review · Q3 · CC6.3
Score61 / 100
RelevanceHigh
FreshnessStale · 112 days
AI summary · what’s missingThe Q3 review covers 38 of 41 in-scope systems. Salesforce, Snowflake and the legacy ERP have no certification recorded. Re-run the campaign for the three systems to restore completeness before the observation window closes.
Create taskRe-run campaign
Weak evidence surfaces weeks before the audit, not during itScored continuously
Continuous monitoring

Catch control drift before the auditor does

A SOC 2 Type II is only as strong as the months in between. Compyl monitors every control continuously, scores your posture in real time, and turns the moment a control slips into a tracked task, not a future finding.

  • Live posture across every Trust Services Criteria control
  • Automatic alerts the moment a control drifts out of compliance
  • Remediation tasks auto-assigned with owners and deadlines
  • A defensible, time-stamped trail across the whole audit window
Continuous monitoring74 controls · checked hourly
Detected09:14 · CloudTrail off in eu-west-2
AlertedOwner: Cloud team
Task openINFRA-2311 · due in 2 days
Verifiedauto re-check
CC7.2 · System monitoringDrifted 09:14 · remediation in progress
Drifting
CC6.6 · Boundary protectionSecurity groups unchanged · last check 08:00
Passing
A defensible, time-stamped trail across the whole windowAudit trail
Collect once, reuse everywhere

Your SOC 2 work becomes a head start on every other framework

SOC 2 shares the majority of its controls with ISO 27001, HIPAA, NIST, and PCI. Compyl cross-maps each control so one piece of evidence satisfies every framework it touches, which is why the second framework costs a fraction of the first.

  • One control mapped to its equivalent across 70+ frameworks
  • Collect evidence once and reuse it across every report
  • See instantly how SOC 2 readiness translates to ISO 27001 or HIPAA
  • Add the next framework without starting the program over
One SOC 2 controlCC6.1 · Logical access controlsMFA enforced for all users · evidence from Okta and AWS IAM1 piece of evidence
Also satisfies
ISO 27001A.5.15 Access control · A.8.5 Secure authentication
Satisfied
HIPAA Security Rule§164.312(a)(1) Access control · (d) Person or entity authentication
Satisfied
NIST CSF 2.0PR.AA-01 · PR.AA-03 Identity & authentication
Satisfied
PCI DSS v4.0.1Req 7.2 · Req 8.4 Multi-factor authentication
Satisfied
+ 70 more frameworks cross-mapped automatically
Know the difference

SOC 2 Type I vs. Type II

The two report types answer different questions. Most customers want Type II, and Type II is where continuous monitoring pays off.

Type I

Designed right, at a point in time

Confirms your controls are suitably designed on a specific date. A faster first milestone that proves the framework is in place.

Scope
Control design at a single date
Timeline
Often achievable in weeks
Best for
A fast first attestation to unblock deals
Type II Most requested

Proven effective, over time

Confirms your controls operated effectively across a monitoring period, typically three to twelve months. The report buyers trust most.

Scope
Operating effectiveness over a period
Timeline
3–12 month observation window
With Compyl
Continuous evidence keeps the whole window clean
Why Compyl for SOC 2

Not a checkbox tool, a continuous compliance engine

Plenty of platforms get you a first SOC 2 report. Compyl was built by security leaders to keep it true every day after, and to make the next framework easy.

01

Continuous, not point-in-time

Evidence and controls stay live year-round, so a Type II window is clean by default.

02

One connected system

Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.

03

125+ integrations

Pulls live data from the stack you already run, so posture reflects reality, not snapshots.

04

Agentic AI

AI maps controls, drafts remediations, and offloads busywork, your team stays in control.

05

Multi-framework by design

SOC 2 evidence carries over to ISO 27001, HIPAA, NIST, and PCI without redoing the work.

Beyond SOC 2

Start with SOC 2, extend to every framework that follows

Compyl cross-maps controls so the work you do for SOC 2 carries straight into the next framework on your roadmap.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
5
Trust Services Criteria mapped to controls and evidence
125+
Native integrations feeding evidence automatically
Real-time
Evidence collection, no manual screenshots
Year-round
Audit readiness instead of a pre-audit scramble

“The complete audit trail that Compyl stores of our compliance has become an essential part of the evidence we provide during our SOC 2 audit.”

RKRyan K.Cyber Security Operations Manager · via G2

What is SOC 2, and how does Compyl help?

SOC 2 is an attestation report, developed by the AICPA, that verifies how a service organization protects customer data. It is assessed by a licensed CPA firm against five Trust Services Criteria, Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory; the others are scoped to the services you provide. Compyl turns SOC 2 from a once-a-year project into an always-on operating state: it connects to your existing systems, collects audit evidence automatically, maps it to the right Trust Services Criteria, monitors every control continuously, and flags drift before it becomes an audit finding, so you stay ready for Type I and Type II year-round.

SOC 2 timeline

How long does SOC 2 take with compliance software?

SOC 2 has fixed parts no software can shorten, the auditor’s fieldwork and the Type II observation window, and moving parts that software collapses. This is where the time goes.

PhaseDone by handWith Compyl
Scoping and gap assessmentSpreadsheet of criteria; weeks of interviewsPre-mapped Trust Services Criteria controls; gaps surfaced from connected systems
Controls and policiesWrite from templates, track ownership in emailPolicy library with owners, approvals and control mapping built in
Evidence collectionScreenshots and exports before every auditLive evidence from 125+ integrations, refreshed continuously
Type I reportPoint-in-time; scramble to assembleAuditor reads the same evidence you see, in the platform
Type II observation window3–12 months; drift goes unnoticedContinuous monitoring flags control failures during the window, not after
After the reportStart over next yearSame controls extend to ISO 27001, HIPAA and 70+ frameworks
FAQ

SOC 2 questions, answered

What is SOC 2 certification?

SOC 2 is an attestation report developed by the AICPA that verifies how a service organization protects customer data. It’s assessed against five Trust Services Criteria, Security, Availability, Processing Integrity, Confidentiality, and Privacy, by a licensed CPA firm. Security (the Common Criteria) is mandatory; the others are included based on the services in scope. Strictly speaking there’s no SOC 2 “certificate”, auditors issue an attestation report, but “certification” is how the market refers to it.

What’s the difference between SOC 2 Type I and Type II?

A Type I report evaluates whether your controls are suitably designed at a single point in time. A Type II report evaluates whether those controls operated effectively over a monitoring period, typically three to twelve months. Customers generally prefer Type II because it proves controls work continuously, not just on the day of the audit.

How does Compyl automate SOC 2 compliance?

Compyl connects to your existing stack, cloud, identity, code, endpoint, and HR systems, and collects audit evidence automatically in real time. It maps each artifact to the relevant Trust Services Criteria controls, monitors those controls continuously, flags drift before it becomes a finding, and assigns remediation tasks. The result is a live audit-readiness posture instead of a pre-audit evidence scramble.

How does Compyl score evidence quality?

Compyl 26.2 introduced Evidence Health, which continuously scores every piece of evidence on three dimensions, relevance (does it support the control?), freshness (is it current?), and completeness (does it tell the whole story?). Scoring runs automatically the moment evidence changes and includes an AI summary of exactly what’s missing, so audit gaps surface weeks ahead of an audit instead of during it.

How long does it take to get SOC 2 compliant?

A Type I can often be achieved in a few weeks once controls are in place. A Type II requires a monitoring period, commonly three to twelve months, during which controls must operate effectively. Compyl shortens preparation by automating evidence collection and control monitoring from day one, so the monitoring window is spent maintaining readiness rather than building it.

Can SOC 2 evidence be reused for other frameworks?

Yes. SOC 2 shares the majority of its controls with ISO 27001, HIPAA, NIST CSF, and PCI DSS. Compyl cross-maps every control so a single piece of evidence satisfies each framework it applies to, which is why the second framework costs a fraction of the first.

Did the SOC 2 Trust Services Criteria change in 2025 or 2026?

No. SOC 2 still uses the AICPA’s 2017 Trust Services Criteria with the points of focus revised in 2022. A 2026 AICPA exposure draft proposes changes to the attestation standards (AT-C 105, 205 and 210), not the criteria, and as proposed would apply to engagements beginning on or after June 15, 2029.

Does SOC 2 cover AI systems?

There is no AI-specific Trust Services Criterion. AI features in scope are evaluated under the existing criteria, such as change management, logical access, processing integrity and confidentiality. Organizations that need AI governance assurance often pair SOC 2 with ISO/IEC 42001, the certifiable AI management system standard.

SOC 2 or ISO 27001: which do I need?

SOC 2 is an attestation report from a CPA firm against the AICPA criteria and is what North American buyers usually ask for. ISO 27001 is a certification of your ISMS by an accredited body, valid for three years with annual surveillance, and more common internationally. The controls overlap heavily, so many companies do both.

GRC your way

Make SOC 2 something you maintain, not something you scramble for

See how Compyl keeps evidence current, controls monitored, and auditors satisfied all year, then carries the same work into the next framework.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies