SOC 2 Trust Services Criteria
The SOC 2 Trust Services Criteria are the criteria a service organization's controls are evaluated against in a SOC 2 examination, published by the AICPA. They apply to the operator of the service, not the software it runs. This page indexes two criteria from the Common Criteria series that bear on software development: system operations and change management.
| Requirement group | Themes |
|---|---|
| CC7 System operations | T6 Automated security verification T13 Vulnerability handling and disclosure |
| CC8.1 Change management | T5 Independent review before a change is accepted T7 Testing and acceptance T8 Change control and traceability |