Skip to content
Obfuscation Hub
Intermediate Self-paced · 8 modules 3 of 8 modules open now

SOC 2 for IT and Security Managers

The manager's working guide to SOC 2: what auditors actually sample, how to design controls that match reality, and how to run an evidence operation that makes the observation window uneventful.

SOC 2 succeeds or fails at the manager level. Executives sponsor it and auditors sample it, but the observation window is won by whoever assigns control owners, keeps the cadences running, and files the evidence — usually the IT or security manager, alongside everything else on their plate.

This path is the working manual for that role. It is deliberately vendor-neutral and tool-agnostic: compliance automation platforms can help, but every concept here works with a spreadsheet, a ticket system, and discipline. The emphasis throughout is on controls that describe your real operation — because the alternative, importing someone else’s control set, is the single most common source of Type II exceptions.

An important boundary: this path prepares you to operate toward an examination. The examination itself is performed only by a licensed CPA firm, and nothing here is a substitute for your auditor’s guidance on their specific expectations.

Modules marked available are open now; the rest arrive as guided lessons in the next release.

Module sequence

Modules marked “Open now” link to working material. The rest arrive as guided lessons in the next release.

  1. 01

    Type I vs. Type II, the Trust Services Criteria, and what the operating team is actually signing up for.

  2. 02

    Scoping: boundaries and criteria selection

    Coming in the next release

    Defining the system, choosing criteria beyond Security deliberately, and the cost of scoping by default.

  3. 03

    Control design that matches reality

    Coming in the next release

    Writing controls from observed behavior, assigning owners and cadences, and avoiding the fictional-company template trap.

  4. 04

    Turning evidence from a quarterly scramble into a byproduct of work — plan it with the SOC 2 evidence planner.

  5. 05

    The quarterly cycle auditors sample first — run it, document it, and practice on realistic data.

  6. 06

    Change, incident, and vendor criteria

    Coming in the next release

    The remaining control families that generate the most requests — and lightweight processes that satisfy them.

  7. 07

    Working with auditors

    Coming in the next release

    Fieldwork mechanics, sampling, handling exceptions honestly, and what distinguishes a smooth engagement.

  8. 08

    Sustaining year over year

    Coming in the next release

    Report renewal rhythm, control changes mid-window, and keeping the program from decaying between audits.

What you will produce

  • A draft system boundary and criteria-selection memo
  • A control-owner matrix with cadences assigned
  • A populated SOC 2 evidence planner
  • A completed access-review cycle documented as audit evidence