CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/soc2-evidence-collector

Build-an-X for SOC 2 Type II evidence collection - per-Trust-Services-Criterion test artifacts (Common Criteria CC1.1 - CC9.2; plus Availability A1, Confidentiality C1, Processing Integrity PI1, Privacy P1 - P9 if in scope); auto-collection from CI logs + audit trails + access logs + change-management records; alignment with Vanta / Drata / Secureframe evidence shapes; observation-period sampling. Use when the team is preparing for SOC 2 Type II audit and needs continuous evidence collection automation.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

evidence-source-map.mdreferences/

SOC 2 evidence source map

In-scope criteria decision

Most SaaS engagements include CC + Availability + Confidentiality. Privacy criteria add when GDPR/CCPA also in scope. Processing Integrity adds for fintech / data-processing SaaS.

Criterion categoryTypical scope decision
CC1 Control EnvironmentAlways
CC2 Communication & InformationAlways
CC3 Risk AssessmentAlways
CC4 MonitoringAlways
CC5 Control ActivitiesAlways
CC6 Logical & Physical AccessAlways
CC7 System OperationsAlways
CC8 Change ManagementAlways
CC9 Risk MitigationAlways
A1 AvailabilityIf uptime SLA committed
C1 ConfidentialityTypical for B2B SaaS
PI1 Processing IntegrityIf data-processing accuracy matters
P1 - P9 PrivacyIf handling PII at scale

Control to evidence source

Map each control to one or more automatable evidence sources:

ControlEvidence sourceCollector pattern
CC6.1 Logical accessIDP audit logs (Okta/Auth0/Keycloak)Daily export of user-access events
CC6.2 Access provisioningOnboarding workflow logsPer-hire ticket + access-grant audit
CC6.3 Access deprovisioningOffboarding workflow logsPer-departure ticket + access-revoke audit
CC7.1 Threat detectionSIEM (Datadog, Splunk) alert logsContinuous alert-history feed
CC7.2 System monitoringAPM (Datadog, New Relic) uptime dataDaily uptime report
CC8.1 Change managementGit PR history + CI deploy logsPer-PR audit (reviewer attribution)
A1.1 Availability monitoringSLO dashboardsMonthly availability report
C1.1 Encryption at restCloud KMS audit logsQuarterly attestation
C1.2 Encryption in transitTLS config auditQuarterly attestation

SKILL.md

tile.json