Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideUse PurpleWASP to structure SOC 2 readiness from engagement scope through criteria, control coverage, implementation, evidence, testing, remediation and audit preparation.
PurpleWASP provides a structured SOC 2 readiness management and audit-preparation workspace. It connects the engagement scope to applicable Trust Services Criteria, organisation Controls, implementation, assessments, evidence, testing, issues, exceptions and readiness decisions.
| Capability | Current PurpleWASP support |
|---|---|
| Engagement setup | Define the service, examination type, Trust Services Categories, system boundary and engagement scope. |
| Criteria workspace | Review the criteria included in the confirmed engagement and the Control candidates associated with them. |
| Control coverage | Adopt relevant Controls and explicitly decide which organisation Controls management intends to rely on for each criterion. |
| Implementation and assessment | Track implementation and record design or operating-effectiveness assessment conclusions for selected organisation Controls. |
| Evidence and testing | Link current evidence, define tests, record test runs and evaluate whether evidence/testing is relevant to the engagement period. |
| Issues, exceptions and remediation | Record deficiencies, exceptions and remediation activity that affect Control or engagement readiness. |
| Operational and audit readiness | Review readiness signals at Control, criterion and engagement level and document management readiness decisions. |
PurpleWASP supports the organisation's SOC 2 readiness programme. It does not replace the independent SOC 2 examination or issue the service auditor's report.
Start from Compliance, select SOC 2 and work through the setup flow. The setup establishes the scope that every later readiness calculation depends on.
The Criteria Workspace shows the criteria in the confirmed engagement together with candidate and selected Control coverage. Keep the matrix collapsed for scanning and expand a criterion when you need to review its Control details.
Do not interpret the number of candidates as a required number of Controls. Management determines the Control set that is appropriate to the actual system and operating model.
Open the Control Coverage Plan to decide which adopted organisation Controls management will rely on for each criterion.
A Control marked Not Applicable in Control Management cannot be selected for SOC 2 coverage until its applicability position is changed.
Selected coverage is only a plan. Open the implementation workbench and confirm how each selected organisation Control is implemented in the scoped system.
Do not mark a Control ready merely because its documentation exists. The readiness view uses implementation and assurance records as separate signals.
Use Evidence and Testing to support the selected Controls with traceable operating proof and repeatable assurance activity.
Use the Issues & Exceptions workspace when the selected Control environment does not fully meet the intended operating position.
Operational Readiness summarises whether selected Controls have the implementation, assessment, evidence, testing and issue state needed to support the engagement. Audit Readiness then brings those signals together at the engagement level.
Use the readiness views—and the available Drivers / Improve Score detail—to identify the specific blockers reducing the internal readiness position, then return to the owning workspace to correct them. A readiness percentage or status should never be treated as a substitute for reviewing the underlying evidence, test result, assessment, issue or exception.
Use PurpleWASP to establish the system description/scope, applicable criteria, selected Control design and supporting evidence at the relevant point in time. Focus on whether the Control environment is suitably designed and represented at that date.
In addition to design, manage the evidence and test record across the defined examination period. Period-relevant evidence and completed test runs become especially important because the readiness question concerns operation over time rather than only a point-in-time design position.
Before auditor handoff, review the engagement as a connected chain:
Scope → Criteria → Selected Controls → Implementation → Assessments → Evidence → Tests → Issues/Exceptions → Readiness decisions.
Use PurpleWASP to make that chain traceable and to identify gaps before fieldwork. The independent service auditor determines the examination procedures, evaluates evidence and issues the SOC 2 report/opinion.
For a detailed beginner-friendly walkthrough of the complete current PurpleWASP SOC 2 readiness workflow, download the implementation guide.
Return to SOC 2 setup, complete the scope and engagement details and confirm the engagement before using the downstream workspace.
Confirm the candidate has been adopted into Control Management and is not marked Not Applicable. Candidate catalogue intelligence alone is not an organisation coverage decision.
Confirm the evidence is linked to the selected organisation Control, is current, and—where Type II period relevance matters—its collection/validity overlaps the engagement period. Also check whether a required final assessment or completed test run is still missing.
Follow the readiness signal back to the underlying Control and issue records. Readiness is a management summary; unresolved issues and exceptions still require explicit review and disposition.