Get Demo
↑

SOC 2 Controls List: Map Controls to the Trust Services Criteria

Build an organisation-defined SOC 2 control inventory mapped to TSC categories and points of focus — outline columns, not a fake fixed AICPA count.

Published: September 2026 Compliance · SOC 2 8–12 min read

A practical SOC 2 controls list is your inventory of organisation-defined controls mapped to the Trust Services Criteria in scope. Use it for readiness, evidence owners, and auditor walkthroughs.

Related: CC1–CC9 · Checklist · Readiness.

Control counts: AICPA publishes criteria and points of focus for the TSC. Your organisation defines the controls that address those criteria. Treat published “100+ control” libraries as examples — not an official fixed checklist every company must adopt unchanged.

Suggested Inventory Columns

Use a spreadsheet or GRC tool with columns like these (request a working template via contact — we do not host a fake public Excel download):

Column
Purpose
Control ID / name
Stable identifier for walkthroughs
TSC mapping
Security CC category and/or optional criteria (A, PI, C, P)
Point(s) of focus
Which illustrative focus areas the control addresses
Owner
Accountable role
Frequency
Continuous / daily / monthly / event-driven
Evidence location
Ticket system, SIEM, IdP, CSA link
Type I / Type II notes
Design narrative vs operating samples needed

Starter Control Groups (Illustrative)

How CyberSilo Helps

CSA maintains a living control-to-evidence map so your list stays current through the observation period.

Turn Your Control List Into Auditor-Ready Evidence

Request a structured controls outline and CSA walkthrough via contact.

Frequently Asked Questions

Is there an official AICPA SOC 2 controls Excel?

No single official fixed control count Excel from AICPA replaces your organisation-defined controls mapped to TSC criteria and points of focus.

Should every company use the same control list?

No. Scope, architecture, and trust commitments differ. Reuse patterns, then tailor.

How does this differ from the checklist?

The controls list is the durable inventory. The compliance checklist is a readiness/progress tracker across programme steps.

SOC 2 hub · Policies · Checklist · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!