{"description":"Runs on the existing Audit engagement with its system description, service commitments, review period, control and risk registers, and available evidence; assesses CC1–CC9 design readiness and consumes reviewed companion assessments for selected optional Trust Services categories. Delivers the criterion-to-control mapping, criterion-level evidence and design conclusions, owned gap register, and approved SOC 2 readiness disposition to management for remediation and examination planning; Type II testing, management-owned PBC preparation and management assertion remain separate workflows.","edges":[{"id":"e-soc2-criteria-mapping-soc2-common-criteria-assessment","source":"soc2-criteria-mapping","target":"soc2-common-criteria-assessment"},{"id":"e-soc2-common-criteria-assessment-soc2-readiness-closure","source":"soc2-common-criteria-assessment","target":"soc2-readiness-closure"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["soc2-readiness"],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"consolidation":{"date":"2026-09-11","note":"Supersedes entries preserve historical catalog lineage and public redirects, not import identity. This new canonical library release does not change installed tenant workflows or rewrite immutable releases.","sources":[{"controls":["UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-HR-06"],"criteria":["CC1.1","CC1.2","CC1.3","CC1.4","CC1.5"],"sourceNodeId":"step-3","sourceTemplateId":"workflow-library:audit-soc2-cc1-control-environment-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-AUDIT-25","UC-GOV-21"],"criteria":["CC2.1","CC2.2","CC2.3"],"sourceNodeId":"step-2","sourceTemplateId":"workflow-library:audit-soc2-cc2-communication-information-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12"],"criteria":["CC3.1","CC3.2","CC3.3","CC3.4"],"sourceNodeId":"step-3","sourceTemplateId":"workflow-library:audit-soc2-cc3-risk-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-RISK-13","UC-RISK-14"],"criteria":["CC4.1","CC4.2"],"sourceNodeId":"step-2","sourceTemplateId":"workflow-library:audit-soc2-cc4-monitoring-activities-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-GOV-14","UC-GOV-16"],"criteria":["CC5.1","CC5.2","CC5.3"],"sourceNodeId":"step-2","sourceTemplateId":"workflow-library:audit-soc2-cc5-control-activities-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-CONFIG-05","UC-CRYPTO-01","UC-NET-01","UC-PHYS-01"],"criteria":["CC6.1","CC6.2","CC6.3","CC6.4","CC6.5","CC6.6","CC6.7","CC6.8"],"sourceNodeId":"step-4","sourceTemplateId":"workflow-library:audit-soc2-cc6-access-controls-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-CONFIG-01","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06"],"criteria":["CC7.1","CC7.2","CC7.3","CC7.4","CC7.5"],"sourceNodeId":"step-3","sourceTemplateId":"workflow-library:audit-soc2-cc7-system-operations-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-CONFIG-02"],"criteria":["CC8.1"],"sourceNodeId":"step-2","sourceTemplateId":"workflow-library:audit-soc2-cc8-change-management-assessment","targetNodeId":"soc2-common-criteria-assessment"},{"controls":["UC-GOV-34","UC-TPRM-02"],"criteria":["CC9.1","CC9.2"],"sourceNodeId":"step-2","sourceTemplateId":"workflow-library:audit-soc2-cc9-risk-mitigation-assessment","targetNodeId":"soc2-common-criteria-assessment"}]},"controlMappingQualification":"Control references cover only the procedures and criteria assessed here. Shared unified-control mappings do not extend the conclusion to other requirements or prove native tenant links or control operation.","controlVerbs":{"UC-ACCESS-01":"tests","UC-ACCESS-03":"tests","UC-ASSET-01":"tests","UC-ASSET-04":"tests","UC-AUDIT-13":"tests","UC-AUDIT-25":"tests","UC-CONFIG-01":"tests","UC-CONFIG-02":"tests","UC-CONFIG-05":"tests","UC-CRYPTO-01":"tests","UC-GOV-04":"tests","UC-GOV-05":"tests","UC-GOV-06":"tests","UC-GOV-07":"tests","UC-GOV-14":"tests","UC-GOV-16":"tests","UC-GOV-21":"tests","UC-GOV-34":"tests","UC-HR-06":"tests","UC-IR-06":"tests","UC-IR-09":"tests","UC-LOG-04":"tests","UC-LOG-06":"tests","UC-NET-01":"tests","UC-PHYS-01":"tests","UC-RISK-04":"tests","UC-RISK-06":"tests","UC-RISK-11":"tests","UC-RISK-12":"tests","UC-RISK-13":"tests","UC-RISK-14":"tests","UC-TPRM-02":"tests"},"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-AUDIT-13","UC-AUDIT-25","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-05","UC-CRYPTO-01","UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-GOV-14","UC-GOV-16","UC-GOV-21","UC-GOV-34","UC-HR-06","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06","UC-NET-01","UC-PHYS-01","UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12","UC-RISK-13","UC-RISK-14","UC-TPRM-02"],"department":"internal-audit","domains":["audit"],"framework":"soc2","kind":"soc2-readiness","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:soc2-readiness"}],"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-readiness-disposition","contentDigest":"sha256:14f2f6568cafdb682d7dafdf0ff401fe56649c1307c627ad67aa0c432bf095ed","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"input","name":"Reviewed availability assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-availability-assessment"},{"direction":"input","name":"Reviewed confidentiality assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-confidentiality-assessment"},{"direction":"input","name":"Reviewed processing integrity assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-processing-integrity-assessment"},{"direction":"input","name":"Reviewed privacy criteria assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-privacy-criteria-assessment"},{"direction":"output","name":"Approved readiness disposition and owned gaps for management PBC preparation and remediation","sourceTemplateId":"workflow-library:controls-soc2-readiness-evidence-cycle"},{"direction":"output","name":"Approved readiness disposition for separately scoped Type II interim testing","sourceTemplateId":"workflow-library:audit-soc2-type2-interim-testing"},{"direction":"output","name":"Readiness disposition and limitations for management-owned assertion preparation","sourceTemplateId":"workflow-library:grc-soc2-reporting-management-assertion"}],"roles":[{"contribution":"expertise","description":"Engagement lead applies expertise to the boundary, category applicability and criteria-to-control mapping; assign this named user before execution.","id":"engagement-lead","nodeIds":["soc2-criteria-mapping"]},{"contribution":"expertise","description":"Assigned assessor evaluates source evidence and drafts signed criterion-level conclusions in the assessment package results. This preparer must not be the independent readiness reviewer.","id":"assigned-assessor","nodeIds":["soc2-common-criteria-assessment"]},{"contribution":"approval","description":"Executive sponsor approves governance and technical commitments and acknowledges findings and action ownership, including CC1, CC3, CC6 and CC8. Assign a distinct native approver on the assessment package and verify the required count remains two after assignment.","id":"executive-sponsor","nodeIds":["soc2-common-criteria-assessment"]},{"contribution":"approval","description":"Security and compliance lead applies domain expertise and approves criterion findings and action ownership, including CC1, CC3, CC6 and CC8. Assign a different native approver from the executive sponsor on the assessment package.","id":"security-compliance-lead","nodeIds":["soc2-common-criteria-assessment"]},{"contribution":"approval","description":"Independent engagement reviewer / audit supervisor challenges every criterion conclusion and evidence package, including selected optional categories, and gives final native readiness approval. Must be separate from package preparation, assessed control operation and both management approvers; verify named tenant assignments before execution.","id":"independent-readiness-reviewer","nodeIds":["soc2-readiness-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:soc2-readiness"},{"source":"workflow-library/workflows/audit/audit-soc2-cc1-control-environment-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc1-control-environment-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc2-communication-information-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc2-communication-information-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc3-risk-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc3-risk-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc4-monitoring-activities-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc4-monitoring-activities-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc5-control-activities-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc5-control-activities-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc6-access-controls-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc6-access-controls-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc7-system-operations-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc7-system-operations-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc8-change-management-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc8-change-management-assessment"},{"source":"workflow-library/workflows/audit/audit-soc2-cc9-risk-mitigation-assessment.json","sourceTemplateId":"workflow-library:audit-soc2-cc9-risk-mitigation-assessment"}],"releaseId":"sha256:14f2f6568cafdb682d7dafdf0ff401fe56649c1307c627ad67aa0c432bf095ed","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-soc2-readiness-disposition","supersedes":["workflow-library:audit-soc2-cc1-control-environment-assessment","workflow-library:audit-soc2-cc2-communication-information-assessment","workflow-library:audit-soc2-cc3-risk-assessment","workflow-library:audit-soc2-cc4-monitoring-activities-assessment","workflow-library:audit-soc2-cc5-control-activities-assessment","workflow-library:audit-soc2-cc6-access-controls-assessment","workflow-library:audit-soc2-cc7-system-operations-assessment","workflow-library:audit-soc2-cc8-change-management-assessment","workflow-library:audit-soc2-cc9-risk-mitigation-assessment"]},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Design-readiness assessment of CC1–CC9 within the documented system boundary and review period. Operating examples support design and implementation observations; this workflow does not issue certification, an examination result or a SOC 2 Type II opinion.","slug":"audit-soc2-readiness-disposition","source":"coworkcanvas-gallery","standards":["soc2"],"teams":["internal-audit"]},"name":"SOC 2 Trust Services Readiness","nodes":[{"data":{"instructions":"**Objective**\nMap criteria, risks, and controls. The engagement lead applies expertise to system boundaries, category applicability and complementary responsibilities.\n\n**Inputs**\n1. Review contracts and commitments, architecture and data flows, inventories, policies, risk assessments, vendor relationships, prior reports, incidents, change plans, and selected Trust Services Criteria.\n2. Use the approved boundary, criteria, risk register, control inventory, policies and procedures, architecture, vendor controls, customer responsibilities, prior findings, and available evidence.\n\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\nBefore execution, resolve the declared roles to named tenant users and verify native assignments and counts on every instantiated step. Assign two distinct people, the executive sponsor and security and compliance lead, to the assessment package. Assign a separate independent readiness reviewer who did not prepare or operate the assessed controls. Library role declarations do not assign users or enforce role membership; changing approvers may replace the required count, so recheck the two-person assignments after any change.\n\n**Procedure**\n1. Interview accountable owners, reconcile the system description to deployed services, identify carve-out or inclusive subservice treatment, define customers and commitments, select categories, and document boundary exclusions and dependencies.\n2. Assess criterion applicability, identify control coverage and gaps, test mapping specificity, document complementary user and subservice controls, trace system-description assertions to support, and challenge duplicate controls that do not address the criterion.\n3. Security common criteria CC1–CC9 remain in scope. For Availability, Confidentiality, Processing Integrity and Privacy, record category selection from service commitments and engagement scope, with the reason for each exclusion. Identify the reviewed companion assessment and its period, boundary, evidence, findings and approval version for each selected category. A missing or incompatible output is an explicit readiness gap, never an assumed pass.\n4. Prepare one evidence index across criteria: identify each artifact once with source, version, period, control references and the criteria it supports.\n\n**Record in AssureSwarm**\n1. Step result: Capture the review period, intended report type and period, services, trust categories, system components, locations, subservice organizations, commitments, boundaries, exclusions, changes, and limitations. Use the Audit.scope and Audit.period_start / Audit.period_end fields only after checking the tenant schema.\n2. Step document: Attach the criterion-to-control mapping and evidence index; document applicability rationale, risks, controls, evidence sources, owners, frequencies, subservice and user controls, system-description references, gaps, and conflicting evidence. Record the document reference in the step result.\n\n**Exit criteria**\nEngagement lead provides expertise: The readiness boundary and selected criteria are unambiguous, subservice treatment is explicit, and material components or commitments are not omitted without documented rationale. Every selected criterion has supported coverage or a visible gap, mappings are specific enough for evidence assessment, and owners agree on responsibility boundaries.\nThe engagement lead checks that the assessment package uses the same reviewed boundary and evidence index; optional categories remain scoped companion assessments, with no executor questionnaire.","kind":"task","label":"Map criteria, risks, and controls","requiredApprovals":1},"id":"soc2-criteria-mapping"},{"data":{"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-AUDIT-25","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-05","UC-CRYPTO-01","UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-GOV-14","UC-GOV-16","UC-GOV-21","UC-GOV-34","UC-HR-06","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06","UC-NET-01","UC-PHYS-01","UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12","UC-RISK-13","UC-RISK-14","UC-TPRM-02"],"instructions":"**Objective**\nAssess CC1–CC9 design and obtain the two management contributions to the criterion-level evidence and action package. The executive sponsor approves governance and technical commitments and action ownership; the security and compliance lead applies expertise to the control design and approves the criterion findings and owned actions.\n\n**Inputs**\nConsume the reviewed system boundary, criteria-to-control mapping and resource-reference index from soc2-criteria-mapping. Use its named systems of record, current policy versions, review period and control references to resolve the evidence below. Record unavailable resources as gaps.\n\n_CC1 Control Environment Assessment_\n- Board & Governance Policy and Information Security Policy (current approved versions with effective dates)\n- Acceptable Use Policy acknowledgment records for employees and contractors\n- Minutes and decisions from the two most recent quarterly governance reviews\n- Signed quarterly attestations from the independent governance advisor, as executed to date under the prospective engagement\n- The linked consolidated controls for tone at the top and board-level oversight\n\nRole definitions for the executive sponsor, technology owner, and security and compliance lead, plus any outsourced security leadership or advisory scope\n- Information Security Policy sections assigning security roles, responsibilities, and authorities\n- Human Resources Security Policy with screening, onboarding agreement, and training records for the assessment window\n- Access documentation mapping role authority to cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform permissions\n\nBoard & Governance Policy and Human Resources Security Policy (accountability, performance, and sanctions provisions)\n- Control-owner assignments on the linked consolidated controls\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- Quarterly oversight reporting covering control metrics, overdue actions, and escalations\n\n_CC2 Communication and Information Assessment_\n- Information Security Objectives with the security metrics catalog and owners\n- The linked consolidated control for quality records and control information\n- A sample of recent control-run records with attached evidence across the operating processes\n- System-generated exports used by recurring controls: cloud identity and access management bindings, the workforce identity and collaboration platform membership, the continuous integration service results\n\nPolicy publication and acknowledgment records across the applicable governing policies\n- Security awareness communications and onboarding materials for the window\n- Customer-facing commitments: terms, support channels, and incident notification obligations\n- Subservice communication evidence: the cloud provider, the workforce identity and collaboration platform, and the source-control platform advisories and status feeds\n\n_CC3 Risk Assessment_\n- Information Security Objectives and business-context documentation\n- Risk Assessment Methodology and the current risk register with scores and owners\n- The most recent enterprise risk assessment run and its sign-off record\n- The linked consolidated controls for objective-setting and periodic risk assessment\n\nFraud-risk entries in the risk register, including management override and misappropriation scenarios\n- The linked consolidated controls for fraud risk and change-impact assessment\n- Segregation-of-duties documentation across cloud identity and access management, the source-control platform, and the billing surface\n- Change-assessment records for significant platform or organizational changes in the window\n\nRisk Management Policy and Risk Assessment Methodology (current approved versions with effective dates)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the risk-assessment series\n\n_CC4 Monitoring Activities Assessment_\n- The linked consolidated control for monitoring risk and control performance\n- Control-run completion data across the operating processes for the window\n- Internal audit program schedule and any completed engagement records\n- Quarterly governance review minutes covering control metrics\n\nThe linked consolidated control for deficiency tracking and remediation\n- The issue register for the window: source, severity, owner, age, and status\n- Escalation records for material deficiencies, including governance review minutes\n- Remediation action plans with due dates and closure evidence\n\n_CC5 Control Activities Assessment_\n- The linked consolidated control for the risk-based control baseline\n- The risk register with treatment mappings from risk to mitigating controls\n- The consolidated control set with its domain coverage (access, change, operations)\n- Segregation-of-duties expectations for control performers and approvers\n\nInformation Security Policy and the policy register with owners, versions, and review dates\n- The linked consolidated control for maintaining approved policies and procedures\n- Process records showing which procedures operationalize which policies\n- Acknowledgment and exception records for the window\n\n_CC6 Logical and Physical Access Controls Assessment_\n- The asset and system inventory identifying protected information assets\n- The linked consolidated controls for account lifecycle, least privilege, and asset inventory\n- Joiner, mover, and leaver records for the window with matching cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform changes\n- Role-to-permission mappings including privileged roles\n\nThe linked consolidated controls for physical access and media handling\n- The carve-out position for the cloud provider data-center physical security with current attestation coverage\n- Endpoint and media inventory: laptops and any removable media in circulation\n- Disposal and sanitization records for devices retired during the window\n\nThe linked consolidated controls for network boundary, encryption, and software restriction\n- Network and service architecture for the customer environments: ingress paths, TLS termination, service-to-service authentication\n- Encryption standards for data at rest and in transit, with key management ownership\n- Endpoint protection and allowed-software configuration for workforce devices\n\nAccess Control Policy, Password & Authentication Policy, and Physical Security Policy (current approved versions)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the access series\n\n_CC7 System Operations Assessment_\n- The linked consolidated controls for configuration baselines and continuous monitoring\n- Vulnerability management records: scans, dependency checks in the continuous integration service, and triage decisions\n- Configuration baselines for the customer environments and drift-detection evidence\n- Monitoring and alerting configuration with escalation routing\n\nThe linked consolidated controls for event evaluation and incident response\n- Incident response plan with declaration criteria, severity levels, and role assignments\n- Event triage records and any declared-incident records for the window\n- Notification obligations toward customers and dependencies on subservice providers\n\nThe linked consolidated control for incident recovery\n- Recovery procedures: infrastructure redeployment, backup restore, and credential rotation paths\n- Postmortem records or recovery exercise results for the window\n- Dependencies on subservice recovery commitments from the cloud provider\n\n_CC8 Change Management Assessment_\n- The linked consolidated control for change authorization and approval\n- the source-control platform configuration: protected branches, merge request approval rules, CI gate definitions\n- A sample of production changes from the window: application code, infrastructure, and database migrations\n- Emergency change records with retrospective approvals\n\nChange Management Policy and Software Development Lifecycle Policy (current approved versions with effective dates)\n- The design conclusion and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the change series\n\n_CC9 Risk Mitigation Assessment_\n- The linked consolidated control for business continuity and contingency planning policy\n- Disruption scenarios in the risk register with their selected mitigations\n- Continuity plan with roles, activation criteria, and recovery priorities\n- Key-person and succession arrangements for critical roles\n\nThe linked consolidated control for vendor due diligence\n- Vendor register with criticality tiers, owners, and review dates\n- Attestation evidence on file: SOC 2 or equivalent reports for the subservice organizations\n- Contracts and data processing terms for vendors touching customer data\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb the detailed assessment activities below; the assigned assessor evaluates the evidence and drafts each criterion conclusion for management review. Original criterion procedures retain their evidence and conclusion requirements within this package.*\n\n_CC1 Control Environment Assessment_\n1. Assessment scope for Assess Tone at the Top & Board Oversight: Assess CC1.1 and CC1.2: the entity demonstrates a commitment to integrity and ethical values, and the board function demonstrates independence from management and exercises oversight of the development and performance of internal control. Assess the ethical culture and governance oversight anchoring the scoped control environment.\n\n2. Read the Board & Governance Policy and confirm it defines standards of conduct, conflict-of-interest handling, and escalation paths that bind the executive sponsor as well as staff.\n\n3. Trace the two most recent quarterly governance reviews end to end: agenda, minutes, decisions, and follow-up actions recorded against the owning process in AssureSwarm.\n\n4. Verify the independent governance advisor's engagement establishes independence from day-to-day management, a defined oversight cadence, and a direct escalation path.\n\n5. Sample Acceptable Use Policy acknowledgments across the workforce and confirm any deviation was handled under the Human Resources Security Policy's sanctions provisions.\n\n6. Compare observed practice against each linked control's statement and record a design conclusion per criterion, noting gaps as candidate findings.\n\n7. Assessment scope for Evaluate Organizational Structure & Competence: Evaluate CC1.3 and CC1.4: management establishes structures, reporting lines, and authorities appropriate for the organization and its documented service architecture, and the organization attracts, develops, and retains competent people in alignment with its objectives.\n\n8. Confirm documented reporting lines match practice: who authorizes risk acceptances, production releases, and vendor commitments, and where each decision escalates.\n\n9. Verify segregation between engineering execution and independent review - including the firm-internal segregation attested through the advisory engagement - is reflected in the role definitions.\n\n10. Inspect screening evidence and signed confidentiality and acceptable-use agreements for personnel onboarded during the window.\n\n11. Review security awareness and role-based training completion and confirm that misses triggered documented follow-up.\n\n12. Test that authority in systems mirrors authority on paper by sampling cloud identity and access management bindings and the source-control platform access for one privileged role and one standard role.\n\n13. Record a design conclusion per criterion and log any mismatch as a candidate finding.\n\n14. Assessment scope for Conclude on Accountability & Control Environment: Assess CC1.5: individuals are held accountable for their internal control responsibilities. Then close the control-environment portion of the readiness assessment by consolidating the conclusions of the Assess Tone at the Top & Board Oversight and Evaluate Organizational Structure & Competence activities.\n\n15. Verify every in-scope control names an accountable owner and that ownership was reassigned promptly for any joiner, mover, or leaver event during the window.\n\n16. Inspect how missed control executions and policy violations were handled: escalation to the security and compliance lead and executive sponsor, sanctions applied under the Human Resources Security Policy, and corrective actions tracked to closure.\n\n17. Confirm performance expectations for roles holding privileged access or approval authority explicitly reference their control responsibilities.\n\n18. Consolidate the design conclusions for the full control-environment series into the readiness summary, classifying each criterion as designed or gap.\n\n19. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC2 Communication and Information Assessment_\n20. Assessment scope for Assess Quality of Control Information: Assess CC2.1: the entity obtains or generates and uses relevant, quality information to support the functioning of internal control. For the scoped service this means the information the control set runs on - control-run evidence in AssureSwarm, the cloud provider audit and application logs, the source-control platform pipeline results, and access exports - is relevant, complete, accurate, and timely enough to support control conclusions.\n\n21. Inventory the information each recurring control consumes and identify its source system, producer, and refresh cadence.\n\n22. For a sample of control runs in the assessment window, verify the evidence attached was system-generated where practical and current as of the run date.\n\n23. Trace two security metrics from the Information Security Objectives to their underlying data and confirm the figures are reproducible.\n\n24. Check that information the controls depend on is retained per requirements and remains retrievable for the audit period.\n\n25. Record a design conclusion for CC2.1 and log information-quality gaps as candidate findings.\n\n26. Assessment scope for Evaluate Internal & External Communication: Evaluate CC2.2 and CC2.3: the entity internally communicates information necessary for internal control to function, including objectives and responsibilities, and communicates with external parties on matters affecting internal control. In scope are onboarding and policy communication to the workforce, and the channels the organization maintains with customers, subservice organizations, and other external parties.\n\n27. Verify each policy names an owner and audience and that publication reached the affected workforce through the acknowledgment flow.\n\n28. Inspect how control responsibilities reach individuals: onboarding materials, role definitions, and recurring security awareness communications.\n\n29. Confirm externally facing channels exist for customers to report security, availability, and privacy concerns, and that inbound reports route to the incident process.\n\n30. Verify subservice advisories and status changes from the cloud provider, the workforce identity and collaboration platform, and the source-control platform are monitored and acted on.\n\n31. Record a design conclusion per criterion and log any communication gap as a candidate finding.\n\n_CC3 Risk Assessment_\n32. Assessment scope for Assess Objectives & Enterprise Risk Identification: Assess CC3.1 and CC3.2: the entity specifies objectives with sufficient clarity to enable identification and assessment of risks, and identifies and analyzes risks across the entity as a basis for determining how they are managed. For the scoped service the anchor artifacts are the Information Security Objectives and the periodic enterprise risk assessment feeding the risk register.\n\n33. Verify objectives are specific enough that a risk can be traced to the objective it threatens - sample three register entries and walk the trace.\n\n34. Confirm the enterprise risk assessment covered the platform, the subservice dependencies (the cloud provider, the workforce identity and collaboration platform, the source-control platform), and the workforce dimension.\n\n35. Check each identified risk carries an analysis: likelihood, impact, inherent and residual scores per the methodology, and a treatment decision.\n\n36. Verify risk owners exist for every open register entry and treatment actions carry target dates.\n\n37. Record a design conclusion per criterion and note gaps as candidate findings.\n\n38. Assessment scope for Evaluate Fraud Risk & Significant Change: Evaluate CC3.3 and CC3.4: the entity considers the potential for fraud in assessing risks, and identifies and assesses changes that could significantly impact the system of internal control. Assess management-override exposure and the available segregation of duties; change assessment must catch platform, subservice, and organizational shifts before they erode the control set.\n\n39. Verify the register carries explicit fraud scenarios - override of controls, unauthorized data access for gain, and misstatement - with analysis and treatments.\n\n40. Assess whether compensating measures for the small-team override risk are designed: independent review through the governance advisor, dual approvals, and immutable audit logging.\n\n41. Inspect how significant changes - new subservice providers, architecture shifts, tenancy model changes, key-person changes - enter risk assessment before adoption.\n\n42. Walk one significant change from the window through its documented risk assessment and approval.\n\n43. Record a design conclusion per criterion with gaps as candidate findings.\n\n44. Assessment scope for Conclude on Risk Assessment Design: Close the risk-assessment portion of the readiness assessment by consolidating the conclusions of the Assess Objectives & Enterprise Risk Identification and Evaluate Fraud Risk & Significant Change activities into a single series verdict against the governing risk policies.\n\n45. Confirm the Risk Management Policy and Risk Assessment Methodology are current, approved, and reflected in the practices the assessment observed.\n\n46. Reconcile every design conclusion recorded in this workflow against its criterion and confirm none is unsupported by attached evidence.\n\n47. Verify each open gap exists as an issue on the readiness audit with a named owner and a target date, and that no gap is silently absorbed into the verdict.\n\n48. Draft the risk-assessment section of the readiness summary, classifying each criterion as designed or gap.\n\n49. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC4 Monitoring Activities Assessment_\n50. Assessment scope for Assess Ongoing & Separate Evaluations: Assess CC4.1: the entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. For the scoped service the design rests on continuous control operation in AssureSwarm with recurring process runs, plus separate evaluations - the internal audit program, quarterly reviews with the governance advisor, and this readiness assessment itself.\n\n51. Verify recurring control runs have a defined cadence and an owner, and that completion is visible on the compliance dashboards.\n\n52. Confirm separate evaluations are scheduled with defined scope and independence - internal audit, the governance advisor's quarterly review, and external assessments.\n\n53. Inspect how monitoring results feed back: who reviews completion rates, missed runs, and stale evidence, and on what cadence.\n\n54. Walk one monitoring cycle end to end, from signal through review to a recorded action.\n\n55. Record a design conclusion for CC4.1 and note monitoring blind spots as candidate findings.\n\n56. Assessment scope for Evaluate Deficiency Communication & Remediation: Evaluate CC4.2: the entity evaluates and communicates internal control deficiencies in a timely manner to the parties responsible for corrective action, including senior management. For the scoped service deficiencies surface as issues in AssureSwarm; the design question is whether they reach the security and compliance lead and the executive sponsor fast enough and are tracked to closure rather than aging quietly.\n\n57. Verify each deficiency was recorded as an issue with severity, an accountable owner, and a remediation date at intake.\n\n58. Trace two deficiencies from detection through communication to the responsible owner and on to closure, confirming timelines match the severity.\n\n59. Confirm material deficiencies reached the executive sponsor and the governance advisor's quarterly review, with decisions minuted.\n\n60. Check that overdue remediation triggers escalation rather than silent date slippage.\n\n61. Record a design conclusion for CC4.2 and log any gap as a candidate finding.\n\n_CC5 Control Activities Assessment_\n62. Assessment scope for Assess Control Selection & Technology General Controls: Assess CC5.1 and CC5.2: the entity selects and develops control activities that mitigate risks to the achievement of objectives to acceptable levels, and selects and develops general control activities over technology. For the scoped service the design rests on a risk-based control baseline mapped to the register, with technology general controls spanning access, change, and operations across the cloud provider, the application hosting service, and the source-control platform.\n\n63. Sample three high residual risks and verify each maps to at least one designed control whose statement actually addresses the risk.\n\n64. Confirm the baseline covers the technology layers the platform depends on: the cloud provider infrastructure and IAM, the application hosting services, the managed database layer, and the source-control platform pipeline.\n\n65. Verify control activities mix types - preventive and detective, automated and manual - proportionate to the risk they mitigate.\n\n66. Check segregation of duties between performing a control and approving its result, with the small-team compensations documented.\n\n67. Record a design conclusion per criterion and log coverage gaps as candidate findings.\n\n68. Assessment scope for Evaluate Policy-to-Procedure Deployment: Evaluate CC5.3: the entity deploys control activities through policies that establish what is expected and procedures that put policies into action. The design question is whether the applicable governing policies anchored by the Information Security Policy translate into operable procedures - the recurring process runs and control activities in AssureSwarm - rather than sitting as shelfware.\n\n69. Verify every policy names an owner, carries an approval and a next review date, and completed its periodic review on schedule.\n\n70. Sample three policies and confirm each is deployed through at least one linked process or control that puts it into action.\n\n71. Confirm policy exceptions follow the documented path - time-boxed, risk-assessed, and approved by the authorized role.\n\n72. Check the accountability wiring: performers can reach the procedure that governs their control activity from the control record itself.\n\n73. Record a design conclusion for CC5.3 and note deployment gaps as candidate findings.\n\n_CC6 Logical and Physical Access Controls Assessment_\n74. Assessment scope for Assess Logical Access Architecture & Credential Lifecycle: Assess CC6.1, CC6.2, and CC6.3: logical access security software and architectures protect information assets; new users are registered and authorized before credentials issue and credentials are removed when access ends; and access is authorized, modified, or removed based on roles with least privilege and segregation of duties. Evaluate the documented customer-isolation architecture where the scoped service hosts multiple customers.\n\n75. Verify the inventory covers the systems holding customer and corporate data, so access architecture decisions rest on a complete asset picture.\n\n76. Confirm the documented customer-isolation model through scoped service identities and segregation of customer resources; verify that credentials cannot cross an unauthorized customer boundary.\n\n77. Trace each leaver in the window to credential removal across cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform within the required interval.\n\n78. Sample privileged and standard role grants and verify authorization preceded issuance and matches the role mapping.\n\n79. Record a design conclusion per criterion and log deviations as candidate findings.\n\n80. Assessment scope for Evaluate Physical Safeguards & Asset Disposal: Evaluate CC6.4 and CC6.5: physical access to facilities and protected information assets is restricted to authorized personnel, and physical protections are discontinued only after the ability to read or recover data has been diminished. Identify direct and inherited physical responsibilities from the documented operating model. Review provider attestations where relied upon, and assess controlled facilities, workforce endpoints, remote workspaces where applicable, and media disposal.\n\n81. Confirm the boundary: which physical responsibilities are inherited from the hosting provider and which remain with the organization, and that the inherited portion is covered by current attestations.\n\n82. Verify workforce physical practice is defined for remote work - screen locking, clear desk, secured devices - and communicated to everyone with production access.\n\n83. Check every retired device in the window has a sanitization or destruction record before leaving control.\n\n84. Verify media containing customer data never leaves the cloud boundary except through approved, encrypted paths.\n\n85. Record a design conclusion per criterion and log gaps as candidate findings.\n\n86. Assessment scope for Assess Boundary Defense, Transmission Protection & Malware Controls: Assess CC6.6, CC6.7, and CC6.8: logical access measures protect against threats from outside the system boundary; transmission, movement, and removal of information is restricted to authorized parties and protected in motion; and controls prevent or detect the introduction of unauthorized or malicious software. The perimeter under review is the application hosting service boundary of each scoped customer environment plus the workforce endpoint fleet.\n\n87. Verify each customer environment exposes only intended ingress: authenticated application hosting service endpoints behind TLS, no stray listeners or publicly readable storage.\n\n88. Confirm encryption in transit end to end and at rest on managed storage, with key management responsibilities documented.\n\n89. Check information movement paths - exports, support access, engineering diagnostics - are restricted to authorized users and logged.\n\n90. Verify endpoint protection and software allow-listing are deployed on workforce devices, with unauthorized-software detection feeding alerts.\n\n91. Record a design conclusion per criterion and log exposures as candidate findings.\n\n92. Assessment scope for Conclude on Access Control Design: Close the logical and physical access portion of the readiness assessment by consolidating the conclusions of the Assess Logical Access Architecture & Credential Lifecycle, Evaluate Physical Safeguards & Asset Disposal, and Assess Boundary Defense, Transmission Protection & Malware Controls activities into a single series verdict against the governing access policies.\n\n93. Confirm the three governing policies are current, approved, and consistent with the access practices the assessment observed.\n\n94. Reconcile the design conclusion for each of the eight criteria against its supporting evidence and flag any unsupported verdict.\n\n95. Verify every open access gap exists as an issue on the readiness audit with a named owner and a target date.\n\n96. Draft the access section of the readiness summary, classifying each criterion as designed or gap.\n\n97. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC7 System Operations Assessment_\n98. Assessment scope for Assess Vulnerability Detection & Anomaly Monitoring: Assess CC7.1 and CC7.2: detection and monitoring procedures identify configuration changes that introduce vulnerabilities and susceptibilities to newly discovered ones, and system components are monitored for anomalies indicative of malicious acts, natural disasters, or errors. The surface is the cloud provider estate and the application hosting services plus the source-control platform pipeline that changes them.\n\n99. Verify hardened baselines exist for the platform's building blocks and that deviations surface as findings rather than persisting silently.\n\n100. Confirm dependency and container scanning runs in the source-control platform pipeline with triage timelines tied to severity.\n\n101. Inspect alert coverage across the customer environments: authentication anomalies, availability signals, and error-rate spikes reach an accountable responder.\n\n102. Walk one vulnerability and one anomaly from detection to disposition.\n\n103. Record a design conclusion per criterion and log blind spots as candidate findings.\n\n104. Assessment scope for Evaluate Event Evaluation & Incident Response: Evaluate CC7.3 and CC7.4: the entity evaluates security events to determine whether they are security incidents, and responds to incidents through a defined program to understand, contain, remediate, and communicate. The design under review is the incident lifecycle from event triage through declared-incident execution, including customer notification duties and coordination with subservice providers.\n\n105. Verify declaration criteria distinguish events from incidents and that triage decisions in the window applied them consistently.\n\n106. Confirm the response program defines roles, containment playbooks, evidence preservation, and communication duties, including customer notification thresholds.\n\n107. Walk one event through triage and, if any incident was declared, through containment, remediation, and communication to closure; otherwise inspect the most recent response exercise.\n\n108. Check that post-incident review feeds corrective actions into the issue register.\n\n109. Record a design conclusion per criterion and log gaps as candidate findings.\n\n110. Assessment scope for Assess Incident Recovery Activities: Assess CC7.5: the entity identifies, develops, and implements activities to recover from identified security incidents. For the scoped service this means restoring affected customer services after a security incident - rebuilding from clean infrastructure definitions and restoring from protected backups - and folding lessons learned back into controls and playbooks.\n\n111. Verify documented recovery procedures exist for the plausible incident classes: compromised credentials, malicious change, data corruption, and service compromise.\n\n112. Confirm recovery is exercisable - a tenant environment can be redeployed from definitions and data restored from backups - with recent evidence of a test.\n\n113. Check recovery includes integrity verification before returning to service, so a compromise is not restored along with the data.\n\n114. Verify postmortems produced corrective actions with owners and dates, and that those actions closed.\n\n115. Record a design conclusion for CC7.5 and log gaps as candidate findings.\n\n_CC8 Change Management Assessment_\n116. Assessment scope for Assess Change Authorization, Testing & Deployment: Assess CC8.1: the entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures. Assess the approved production change path: independently reviewed change requests, automated test gates, protected branches, infrastructure definitions, and database migrations.\n\n117. Verify the pipeline enforces the lifecycle: no direct pushes to protected branches, independent review before merge, and green CI gates before deploy.\n\n118. Sample changes across the three classes - application code, infrastructure definitions, database migrations - and confirm each shows authorization, testing, approval, and deployment evidence.\n\n119. Check segregation between author and approver holds in practice, including the small-team case with documented compensations.\n\n120. Verify emergency changes follow the expedited path and receive retrospective review within the required interval.\n\n121. Record a design conclusion for CC8.1 and log deviations as candidate findings.\n\n122. Assessment scope for Conclude on Change Management Design: Close the change-management portion of the readiness assessment by consolidating the conclusion of the Assess Change Authorization, Testing & Deployment activity into a series verdict against the governing change policies.\n\n123. Confirm both governing policies are current, approved, and consistent with the observed pipeline practice, including the emergency path.\n\n124. Reconcile the CC8.1 design conclusion against its supporting evidence and flag anything unsupported.\n\n125. Verify every open change gap exists as an issue on the readiness audit with a named owner and a target date.\n\n126. Draft the change section of the readiness summary, classifying the criterion as designed or gap.\n\n127. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the assessment activity instead of closing it here.\n\n_CC9 Risk Mitigation Assessment_\n128. Assessment scope for Assess Business Disruption Risk Mitigation: Assess CC9.1: the entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions. For the scoped service, assess disruptions including hosting-region loss, key-person unavailability, subservice failure, and funding interruption; the design anchor is the business continuity and contingency planning framework.\n\n129. Verify the register carries the disruption scenarios that matter for the operating model and each carries a selected mitigation, not just an acceptance.\n\n130. Confirm the continuity plan assigns roles and activation criteria and covers the platform's dependency on the cloud provider regional services.\n\n131. Check key-person risk carries concrete mitigations: documented runbooks, credential escrow, and cross-training or advisory cover.\n\n132. Verify mitigation activities have owners and review dates, so they survive personnel and platform change.\n\n133. Record a design conclusion for CC9.1 and log gaps as candidate findings.\n\n134. Assessment scope for Evaluate Vendor & Business Partner Risk Management: Evaluate CC9.2: the entity assesses and manages risks associated with vendors and business partners. Use the approved vendor register to identify material cloud, identity, development-platform, and advisory dependencies; document the significance of each relationship.\n\n135. Verify every active vendor appears in the register with a criticality tier, an owner, and a next review date.\n\n136. Confirm due diligence preceded engagement for vendors touching customer data and was refreshed on schedule for the critical tier.\n\n137. Inspect the most recent attestation review for each subservice organization, including exceptions noted and complementary controls adopted in response.\n\n138. Check exit thinking exists for the concentrated dependencies: what happens if a critical vendor degrades, and who decides.\n\n139. Record a design conclusion for CC9.2 and log gaps as candidate findings.\n\n140. Keep a separate conclusion for each criterion, with the assessor identity, evidence references, applicable controls, design or implementation gaps and rationale. Preserve adverse and conflicting evidence. The executive sponsor and security and compliance lead each review this exact package version and acknowledge findings, action ownership and commitments through separate native approvals; an unresolved objection prevents completion and requires correction. Their approval does not replace the independent readiness review at soc2-readiness-closure.\n\n**Record in AssureSwarm**\nUse the markdown step result for the signed assessor conclusions, criterion-to-evidence references and limitations; use attached step documents for the workpapers listed below. After checking the tenant schema, create or update each gap as an Issue (issue_type: finding, source: internal_audit, severity, issue_owner) and link it to the existing Audit and affected Control records. Record each corrective action on a linked Remediation item using plan, action_owner and target_date. If those fields or the Remediation type are unavailable, retain the action plan, owner and target date in the step workpaper and disclose the missing destination; do not invent Issue fields. Describe criterion identifiers in the workpaper and Issue; no Criterion item is required. Bind both native management approvals to the same reviewed package version. Substantive changes require renewed approvals before downstream reliance.\n\n_CC1 Control Environment Assessment_\nAttach the governance minutes, the advisor attestations, and the acknowledgment export to this step. Raise each design gap as an issue linked to the readiness audit, referencing the affected control by title, and note the design conclusion in the step record.\n\nAttach the role definitions, sampled screening and training evidence, and the permission exports to this step. Link each gap to the affected control, raise it as an issue on the readiness audit, and capture the rationale for each conclusion in the step record.\n\nRecord the consolidated conclusion on this step and attach the control-environment section of the readiness summary. Confirm every gap exists as an issue linked to the readiness audit with a named owner and a target date before requesting approval.\n\n_CC2 Communication and Information Assessment_\nAttach the information inventory, sampled control-run evidence, and metric traces to this step. Raise each information-quality gap as an issue linked to the readiness audit, referencing the affected control by title.\n\nAttach acknowledgment exports, sample communications, and the external-channel inventory to this step. Raise gaps as issues linked to the readiness audit and record the conclusion for each criterion in the step record.\n\n_CC3 Risk Assessment_\nAttach the risk register export and the assessment sign-off to this step. Raise each gap as an issue linked to the readiness audit and record the design conclusions in the step record.\n\nAttach the fraud-risk extract, override compensations, and the sampled change assessment to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the risk-assessment section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC4 Monitoring Activities Assessment_\nAttach the cadence inventory, completion metrics, and review minutes to this step. Raise blind spots as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the issue register export and the traced deficiency records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC5 Control Activities Assessment_\nAttach the risk-to-control mapping sample and the domain coverage summary to this step. Raise coverage gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the policy register export and the sampled policy-to-procedure traces to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC6 Logical and Physical Access Controls Assessment_\nAttach the inventory extract, lifecycle samples, and permission exports to this step. Raise deviations as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the carve-out summary, endpoint inventory, and disposal records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the architecture summary, encryption standard, and endpoint configuration evidence to this step. Raise exposures as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the access section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC7 System Operations Assessment_\nAttach scan samples, baseline evidence, and alert-routing configuration to this step. Raise blind spots as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach triage samples, the response plan, and walkthrough records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach recovery procedures, exercise evidence, and postmortem records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC8 Change Management Assessment_\nAttach the pipeline configuration export and the sampled change records to this step. Raise deviations as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the change section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC9 Risk Mitigation Assessment_\nAttach the disruption-scenario extract and continuity plan to this step. Raise gaps as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the vendor register export and attestation review notes to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n**Exit criteria**\n_CC1 Control Environment Assessment_\nCC1.1 and CC1.2 each carry a documented design conclusion supported by attached evidence, and every candidate finding has a named owner and a target date. CC1.3 and CC1.4 each carry a supported design conclusion across structures, reporting lines, and competence practices, and any divergence between documented authority and system permissions is logged as an issue with an owner and a target date. All five control-environment criteria (CC1.1–CC1.5) carry a supported design conclusion, both approvers have signed off on this step, and no control-environment gap remains without an owner, a target date, and a linked issue.\n\n_CC2 Communication and Information Assessment_\nCC2.1 carries a documented design conclusion supported by attached evidence, and every information-quality gap has a named owner and a target date. CC2.2 and CC2.3 each carry a documented design conclusion, every communication gap is logged with a named owner and a target date, and the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC3 Risk Assessment_\nCC3.1 and CC3.2 each carry a documented design conclusion supported by attached evidence, and identified gaps have named owners and target dates. CC3.3 and CC3.4 each carry a documented design conclusion, and every gap is logged with a named owner and a target date. All four criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no risk-assessment gap remains without an owner, a target date, and a linked issue.\n\n_CC4 Monitoring Activities Assessment_\nCC4.1 carries a documented design conclusion supported by attached evidence, and every monitoring blind spot has a named owner and a target date. CC4.2 carries a documented design conclusion, both traced deficiencies show timely communication and closure, and remaining gaps carry named owners and target dates.\n\n_CC5 Control Activities Assessment_\nCC5.1 and CC5.2 each carry a documented design conclusion, and every coverage gap is logged with a named owner and a target date. CC5.3 carries a documented design conclusion, sampled policies trace to operating procedures, and every deployment gap has a named owner and a target date.\n\n_CC6 Logical and Physical Access Controls Assessment_\nCC6.1, CC6.2, and CC6.3 each carry a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC6.4 and CC6.5 each carry a documented design conclusion, the inherited-versus-retained boundary is explicit, and every gap has a named owner and a target date. CC6.6, CC6.7, and CC6.8 each carry a documented design conclusion supported by attached evidence, and every exposure has a named owner and a target date. All eight criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no access gap remains without an owner, a target date, and a linked issue.\n\n_CC7 System Operations Assessment_\nCC7.1 and CC7.2 each carry a documented design conclusion supported by attached evidence, and every blind spot has a named owner and a target date. CC7.3 and CC7.4 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC7.5 carries a documented design conclusion supported by attached evidence, and every recovery gap has a named owner and a target date.\n\n_CC8 Change Management Assessment_\nCC8.1 carries a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC8.1 carries a supported design conclusion, both approvers have signed off on this step, and no change gap remains without an owner, a target date, and a linked issue.\n\n_CC9 Risk Mitigation Assessment_\nCC9.1 carries a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC9.2 carries a documented design conclusion supported by attached evidence, and every vendor gap has a named owner and a target date.\n\nThe executive sponsor and security and compliance lead are two distinct assigned approvers. Both have approved this version, every criterion has a signed assessor conclusion and evidence or a visible gap, and all gaps have owners and dates. The independent readiness conclusion remains pending until soc2-readiness-closure.","kind":"task","label":"Review common criteria design","performedBy":{"note":"Agent retrieves authorized evidence and prepares attachments. The assigned assessor evaluates evidence and drafts signed criterion conclusions; management acknowledges findings and actions through native approvals. The separate independent readiness reviewer challenges all conclusions before final disposition.","primitives":["coach-document-upload","coach-query-data"]},"requiredApprovals":2},"id":"soc2-common-criteria-assessment"},{"data":{"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-AUDIT-13","UC-AUDIT-25","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-05","UC-CRYPTO-01","UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-GOV-14","UC-GOV-16","UC-GOV-21","UC-GOV-34","UC-HR-06","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06","UC-NET-01","UC-PHYS-01","UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12","UC-RISK-13","UC-RISK-14","UC-TPRM-02"],"instructions":"**Objective**\nApprove SOC 2 readiness record. The independent readiness reviewer challenges evidence sufficiency and approves the examination-planning disposition.\n\n**Inputs**\nConsume the reviewed assessment package from soc2-common-criteria-assessment, with its two management approvals, signed assessor conclusions, criterion evidence and owned gap register. Also consume the reviewed companion assessment for each selected optional category; exclusions must trace to the approved scope.\n1. Review mapped controls, walkthroughs, sample evidence across the intended period, system-description draft, incidents, exceptions, vendor reports, gap inventory, remediation plans, and readiness milestones.\n2. Review all stage evidence, final mapping, system-description version, gap and remediation tracker, readiness result, subservice and user responsibilities, changes, limitations, and stakeholder comments.\n\n**Procedure**\n1. Inspect evidence quality and continuity, identify missing operating history, validate design and implementation observations, assess gap impact by criterion, sequence remediation and evidence generation, and avoid presenting readiness work as examination testing.\n2. Trace the disposition to criterion-level evidence, verify gaps and dependencies remain visible, reconcile document versions and scope, challenge unsupported timing, and return inconsistencies or hidden limitations for correction.\n3. Independently challenge all 33 common-criteria conclusions (CC1.1–CC1.5, CC2.1–CC2.3, CC3.1–CC3.4, CC4.1–CC4.2, CC5.1–CC5.3, CC6.1–CC6.8, CC7.1–CC7.5, CC8.1, CC9.1–CC9.2). For each, record the independent reviewer conclusion, evidence sufficiency, control mapping and remaining gap; reconcile the four optional categories to the approved engagement scope and applicable reviewed companion outputs.\n4. Verify both named management roles approved the exact package versions and that the reviewer is independent of preparation and operation of the assessed controls. Return unsupported or disputed conclusions to the owning assessment package; substantive corrections require its renewed dual approvals and this independent review. Management acceptance cannot cure insufficient evidence or override the independent conclusion.\n5. Hand the approved disposition, conditions and action tracker to management for remediation and examination planning. Keep SOC 2 Type II interim testing, PBC evidence preparation and management assertion with their separate owners and workflows. The service auditor retains responsibility for any SOC opinion.\n\n**Record in AssureSwarm**\n1. Step result: Document the readiness result by criterion, evidence reviewed, design or implementation gaps, operating-history needs, remediation owner and due date, dependencies, conditions, and proposed examination timing.\n2. Step document: Attach the SOC 2 readiness summary and final evidence index; capture the authorized reviewer, final boundary and mapping references, readiness result, conditions, gaps, remediation owners and dates, system-description status, intended next step, limitations, and reassessment triggers. The native approval records the independent reviewer’s decision against this version.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the evidence-based readiness disposition, conditions and gaps are fully owned, and no claim of SOC 2 certification or auditor opinion is made. The authorized reviewer accepts a management readiness record for planning purposes; closure is not certification and does not predict or replace a service auditor’s opinion.\nEvery common criterion and selected optional category has an independent conclusion with evidence or an explicit limitation. The independent readiness reviewer has recorded native approval; the two management approvals remain separate and traceable.","kind":"task","label":"Approve SOC 2 readiness record","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"Independent readiness reviewer","ermPhase":"report","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"soc2-readiness-closure"}],"sourceTemplateId":"workflow-library:audit-soc2-readiness-disposition"}
