SOC 2 Control Coverage Checker
Check which SOC 2 controls you've implemented across TSC categories.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Check your SOC 2 control coverage
SOC 2 is organised around trust service criteria, and knowing which controls you have implemented across them shows your readiness. This tool checks which SOC 2 controls you have implemented across the TSC categories, so gaps are visible.
Why coverage across categories matters
SOC 2’s trust service criteria, security, availability, processing integrity, confidentiality and privacy, each cover a dimension of protecting customer data, and a report covers the categories you choose. Tracking which controls you have implemented across those categories shows where you are ready and where coverage is thin, so you can close gaps before the audit rather than discover them during it. Seeing coverage by category also helps you decide which criteria to include in scope, since only those you can support with controls belong there.
A tool, not legal advice
This is a practical aid, not legal advice, and regulations change and vary by circumstance. Confirm your obligations with a qualified professional before relying on any assessment or generated document. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input describes your compliance posture.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What are the trust service criteria?
Security, availability, processing integrity, confidentiality and privacy, the five categories SOC 2 uses. A report covers the ones you include in scope.
Why track coverage by category?
Because it shows where you are ready and where coverage is thin, so you can close gaps before the audit and decide which criteria to include in scope.
Is security always in scope?
Security is the common criterion included in essentially all SOC 2 reports; the others are added based on what is relevant to your service and customers.
How does this help preparation?
By making gaps visible ahead of the audit, so you close them deliberately rather than incurring findings for missing controls.
Is my input uploaded?
No. The tool runs entirely in your browser.
Privacy & Security
Checking done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.