Compliance guide

Prepare for SOC 2 with PurpleWASP

Use PurpleWASP to structure SOC 2 readiness from engagement scope through criteria, control coverage, implementation, evidence, testing, remediation and audit preparation.

Compliance Manager, Security Manager, Control Owner or authorised contributor Ongoing readiness programme Updated 18 September 2026

What PurpleWASP SOC 2 does today

PurpleWASP provides a structured SOC 2 readiness management and audit-preparation workspace. It connects the engagement scope to applicable Trust Services Criteria, organisation Controls, implementation, assessments, evidence, testing, issues, exceptions and readiness decisions.

Use PurpleWASP to answer the management-side readiness questions. Which criteria apply? Which Controls are we relying on? Are they implemented? Do we have current evidence? Have they been tested? Are there unresolved issues? Does the Type II period contain sufficient operating evidence? What is blocking audit readiness?
CapabilityCurrent PurpleWASP support
Engagement setupDefine the service, examination type, Trust Services Categories, system boundary and engagement scope.
Criteria workspaceReview the criteria included in the confirmed engagement and the Control candidates associated with them.
Control coverageAdopt relevant Controls and explicitly decide which organisation Controls management intends to rely on for each criterion.
Implementation and assessmentTrack implementation and record design or operating-effectiveness assessment conclusions for selected organisation Controls.
Evidence and testingLink current evidence, define tests, record test runs and evaluate whether evidence/testing is relevant to the engagement period.
Issues, exceptions and remediationRecord deficiencies, exceptions and remediation activity that affect Control or engagement readiness.
Operational and audit readinessReview readiness signals at Control, criterion and engagement level and document management readiness decisions.

Current capability boundary

PurpleWASP supports the organisation's SOC 2 readiness programme. It does not replace the independent SOC 2 examination or issue the service auditor's report.

Do not describe the current capability as end-to-end SOC 2 automation or SOC 2 certification. The current product supports readiness, Control management, evidence, testing, remediation and audit preparation. The independent examination and opinion remain with the appropriately qualified service auditor.
  • PurpleWASP does not issue a SOC 2 report.
  • PurpleWASP readiness indicators are management/internal readiness signals, not an auditor opinion.
  • Candidate mappings are PurpleWASP intelligence suggestions, not a mandatory checklist that must all be adopted.
  • Automated evidence integrations and broad continuous Control monitoring are not yet the whole SOC 2 operating model; use the records and integrations actually configured for your organisation.

1. Set up and confirm the SOC 2 engagement

Start from Compliance, select SOC 2 and work through the setup flow. The setup establishes the scope that every later readiness calculation depends on.

  1. Select the Trust Services Categories relevant to the service. Security is foundational; add other categories only where they are part of the intended examination scope.
  2. Describe the service/system and discover the people, processes, technology, data, infrastructure and dependencies that form the system boundary.
  3. Choose Type I or Type II and establish the engagement period where applicable.
  4. Review subservice organisations, complementary user entity considerations and relevant boundary assumptions.
  5. Review and confirm the engagement before treating the downstream criteria and readiness views as authoritative.
Illustrated screen map of the current SOC 2 scope setup. Confirm the engagement boundary before relying on downstream readiness calculations.

2. Review the Criteria Workspace

The Criteria Workspace shows the criteria in the confirmed engagement together with candidate and selected Control coverage. Keep the matrix collapsed for scanning and expand a criterion when you need to review its Control details.

  • Candidate means PurpleWASP has a potential Control-to-criterion mapping.
  • Adopted candidate means the Control exists in the organisation's Control Management workspace.
  • Selected means management has explicitly chosen that organisation Control as part of the criterion coverage plan.

Do not interpret the number of candidates as a required number of Controls. Management determines the Control set that is appropriate to the actual system and operating model.

The Criteria Workspace keeps the criterion summary visible while detailed Control coverage can be expanded only when needed.

3. Decide the organisation Control coverage plan

Open the Control Coverage Plan to decide which adopted organisation Controls management will rely on for each criterion.

  1. Review candidate Controls and their mapping strength.
  2. If a useful candidate has not yet been adopted, review/adopt it in Control Management.
  3. For an adopted Control, choose Use for coverage when management intends to rely on it.
  4. Choose Do not use when the candidate is not part of the organisation's intended coverage approach.
  5. Use Clear decision if the mapping should return to an unreviewed state.

A Control marked Not Applicable in Control Management cannot be selected for SOC 2 coverage until its applicability position is changed.

Use the Control Coverage Plan to turn candidate intelligence into explicit management coverage decisions.

4. Implement and assess the selected Controls

Selected coverage is only a plan. Open the implementation workbench and confirm how each selected organisation Control is implemented in the scoped system.

  • Confirm ownership and implementation status.
  • Connect relevant system/Asset implementation context where available.
  • Perform design assessment to determine whether the Control is suitably designed for its intended purpose.
  • For operating-effectiveness readiness, record the appropriate final assessment conclusion based on the operating evidence available.

Do not mark a Control ready merely because its documentation exists. The readiness view uses implementation and assurance records as separate signals.

5. Build the evidence and testing record

Use Evidence and Testing to support the selected Controls with traceable operating proof and repeatable assurance activity.

  • Link evidence to the organisation Control it supports and record enough source/date/validity context for a reviewer.
  • For Type II, confirm that the evidence validity or collection period overlaps the engagement window where that evidence is intended to support operating effectiveness.
  • Define active tests for Controls that require testing.
  • Record test runs and results rather than treating the existence of a test definition as proof that a Control was tested during the period.
  • Raise an issue when assessment, evidence or testing identifies a deficiency requiring follow-up.
Evidence, assessments and test activity remain distinct assurance records. Use them together when evaluating Control readiness.

6. Resolve issues, exceptions and remediation

Use the Issues & Exceptions workspace when the selected Control environment does not fully meet the intended operating position.

  • Record active issues and their severity, ownership and remediation state.
  • Use exceptions where a temporary approved departure is being governed rather than silently accepted.
  • Track remediation to evidence-based closure and reassess readiness after the underlying state changes.
  • Pay particular attention to high/critical issues and unresolved exceptions when preparing the engagement for auditor review.

7. Review Operational Readiness and Audit Readiness

Operational Readiness summarises whether selected Controls have the implementation, assessment, evidence, testing and issue state needed to support the engagement. Audit Readiness then brings those signals together at the engagement level.

The SOC 2 dashboard is a management readiness view. Follow any warning or gap back to the underlying authoritative record.

Use the readiness views—and the available Drivers / Improve Score detail—to identify the specific blockers reducing the internal readiness position, then return to the owning workspace to correct them. A readiness percentage or status should never be treated as a substitute for reviewing the underlying evidence, test result, assessment, issue or exception.

Audit Readiness consolidates management-side readiness and remediation signals before the independent service auditor performs the examination.

Type I and Type II readiness

Type I

Use PurpleWASP to establish the system description/scope, applicable criteria, selected Control design and supporting evidence at the relevant point in time. Focus on whether the Control environment is suitably designed and represented at that date.

Type II

In addition to design, manage the evidence and test record across the defined examination period. Period-relevant evidence and completed test runs become especially important because the readiness question concerns operation over time rather than only a point-in-time design position.

Prepare for the independent service auditor

Before auditor handoff, review the engagement as a connected chain:

Scope → Criteria → Selected Controls → Implementation → Assessments → Evidence → Tests → Issues/Exceptions → Readiness decisions.

Use PurpleWASP to make that chain traceable and to identify gaps before fieldwork. The independent service auditor determines the examination procedures, evaluates evidence and issues the SOC 2 report/opinion.

Full SOC 2 implementation guide

For a detailed beginner-friendly walkthrough of the complete current PurpleWASP SOC 2 readiness workflow, download the implementation guide.

Download the SOC 2 implementation guide

Common problems

No confirmed engagement is available

Return to SOC 2 setup, complete the scope and engagement details and confirm the engagement before using the downstream workspace.

A candidate Control cannot be selected

Confirm the candidate has been adopted into Control Management and is not marked Not Applicable. Candidate catalogue intelligence alone is not an organisation coverage decision.

Evidence exists but readiness still shows a gap

Confirm the evidence is linked to the selected organisation Control, is current, and—where Type II period relevance matters—its collection/validity overlaps the engagement period. Also check whether a required final assessment or completed test run is still missing.

A readiness indicator looks positive but an issue remains open

Follow the readiness signal back to the underlying Control and issue records. Readiness is a management summary; unresolved issues and exceptions still require explicit review and disposition.